CVE-2026-2230
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-2230 is an Insecure Direct Object Reference (IDOR) vulnerability in the Booking Calendar plugin for WordPress, affecting all versions up to and including 10.14.14. The flaw exists in the handle_ajax_save function, which fails to validate a user-controlled key, allowing authenticated attackers with Subscriber-level access (and booking permissions granted by an Administrator) to modify other users' plugin settings. It was published on February 18, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (Red Hat CVE).

Technical details

The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), where the handle_ajax_save function in the Booking Calendar WordPress plugin accepts a user-supplied key to identify the target settings record without verifying that the requesting user is authorized to modify that record. An authenticated attacker with at least Subscriber-level access and booking permissions can craft an AJAX request referencing another user's settings object, enabling unauthorized modification of booking calendar display options and related plugin configurations (Red Hat CVE, Infinitsec).

Impact

Successful exploitation allows an authenticated attacker to modify other users' Booking Calendar plugin settings, such as display options, which can disrupt the booking calendar functionality for targeted users. The impact is limited to integrity (low), with no confidentiality or availability impact reported. While the vulnerability does not enable remote code execution or data exfiltration, it can degrade the user experience and operational reliability of booking workflows on affected WordPress sites (Red Hat CVE).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-2230. The EPSS score is approximately 0.02%, indicating a very low probability of exploitation in the near term. The vulnerability requires the attacker to already be authenticated with at least Subscriber-level access and to have been granted booking permissions by an Administrator, which significantly limits the attack surface. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Red Hat CVE).

Exploitation steps

  1. Obtain authenticated access: Register or obtain credentials for a WordPress account with at least Subscriber-level privileges on the target site, and ensure booking permissions have been granted by an Administrator.
  2. Identify target user settings: Enumerate or guess the user-controlled key (e.g., a user ID or settings record identifier) associated with another user's Booking Calendar plugin settings.
  3. Craft malicious AJAX request: Send a crafted HTTP POST request to the WordPress AJAX endpoint (e.g., wp-admin/admin-ajax.php) invoking the handle_ajax_save function, substituting the target user's key in the request parameters.
  4. Modify target settings: The server processes the request without validating ownership, applying the attacker-supplied settings (e.g., altered display options) to the victim user's booking calendar configuration, disrupting their booking calendar functionality (Infinitsec, Red Hat CVE).

Indicators of compromise

  • Logs: WordPress access logs showing repeated POST requests to wp-admin/admin-ajax.php with the handle_ajax_save action from a low-privileged user account, particularly targeting user IDs or settings keys that do not belong to the requesting user.
  • Application: Unexpected changes to Booking Calendar display settings or configuration for users who did not initiate those changes, potentially reported by affected users.
  • Network: Unusual AJAX request patterns from a single authenticated session targeting multiple different user setting keys in rapid succession.

Mitigation and workarounds

Users should update the Booking Calendar WordPress plugin to a version beyond 10.14.14 that includes a fix for this vulnerability. Until a patched version is available or applied, administrators should audit which users have been granted booking permissions and restrict those permissions to trusted accounts only. Monitoring WordPress AJAX logs for anomalous handle_ajax_save requests can help detect potential abuse (Red Hat CVE, Infinitsec).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-14444HIGH7.5
  • wp-fusion
NoYesSep 07, 2026
CVE-2026-6431HIGH7.2
  • profile-builder
NoYesSep 07, 2026
CVE-2026-12757MEDIUM6.5
  • email-subscribers
NoYesSep 07, 2026
CVE-2026-8279MEDIUM5.3
  • learning-management-system
NoYesSep 07, 2026
CVE-2026-4945MEDIUM5.3
  • otter-blocks
NoYesSep 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management