
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2230 is an Insecure Direct Object Reference (IDOR) vulnerability in the Booking Calendar plugin for WordPress, affecting all versions up to and including 10.14.14. The flaw exists in the handle_ajax_save function, which fails to validate a user-controlled key, allowing authenticated attackers with Subscriber-level access (and booking permissions granted by an Administrator) to modify other users' plugin settings. It was published on February 18, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (Red Hat CVE).
The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), where the handle_ajax_save function in the Booking Calendar WordPress plugin accepts a user-supplied key to identify the target settings record without verifying that the requesting user is authorized to modify that record. An authenticated attacker with at least Subscriber-level access and booking permissions can craft an AJAX request referencing another user's settings object, enabling unauthorized modification of booking calendar display options and related plugin configurations (Red Hat CVE, Infinitsec).
Successful exploitation allows an authenticated attacker to modify other users' Booking Calendar plugin settings, such as display options, which can disrupt the booking calendar functionality for targeted users. The impact is limited to integrity (low), with no confidentiality or availability impact reported. While the vulnerability does not enable remote code execution or data exfiltration, it can degrade the user experience and operational reliability of booking workflows on affected WordPress sites (Red Hat CVE).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-2230. The EPSS score is approximately 0.02%, indicating a very low probability of exploitation in the near term. The vulnerability requires the attacker to already be authenticated with at least Subscriber-level access and to have been granted booking permissions by an Administrator, which significantly limits the attack surface. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Red Hat CVE).
wp-admin/admin-ajax.php) invoking the handle_ajax_save function, substituting the target user's key in the request parameters.wp-admin/admin-ajax.php with the handle_ajax_save action from a low-privileged user account, particularly targeting user IDs or settings keys that do not belong to the requesting user.Users should update the Booking Calendar WordPress plugin to a version beyond 10.14.14 that includes a fix for this vulnerability. Until a patched version is available or applied, administrators should audit which users have been granted booking permissions and restrict those permissions to trusted accounts only. Monitoring WordPress AJAX logs for anomalous handle_ajax_save requests can help detect potential abuse (Red Hat CVE, Infinitsec).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."