rootpwn

low · CVSS v3 3.7 · EPSS 0.00156

CVE-2026-39601

WPdevelop Booking Calendar plugin contains a race condition that can be triggered by concurrent booking requests, potentially allowing unaut

Overview

WPdevelop Booking Calendar plugin contains a race condition that can be triggered by concurrent booking requests, potentially allowing unauthorized manipulation of booking data. The flaw exists in all versions up to 11.8.4 and may lead to data corruption or service disruption.

Description

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in WPdevelop Booking Calendar booking allows Leveraging Race Conditions.This issue affects Booking Calendar: from n/a through 11.8.4.

Impact

Confidentiality: possible exposure of booking details. Integrity: unauthorized modification of booking records. Availability: potential service disruption due to corrupted data. Defenders: WordPress site administrators and plugin maintainers.

Remediation

Update Booking Calendar to version 11.8.5 or later. If an update is not immediately possible, disable concurrent booking submissions or implement request throttling to mitigate race conditions. Apply any vendor‑provided patch or configuration change that enforces proper synchronization.

Risk context

The CVSS v3 score of 3.7 and an EPSS of 0.00156 indicate a very low likelihood of exploitation; this vulnerability is low priority but should still be addressed in routine maintenance.

Affected products

  • WPdevelop Booking Calendar

Scores

Severity
low
CVSS v2
2.6
CVSS v3
3.7
CVSS v4
—
EPSS
0.00156

race condition booking-calendar wp-plugin low-severity wpdevelop confidentiality integrity availability

← All CVEs