CVE-2026-39601: Wpdevelop Booking Calendar

Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in WPdevelop Booking Calendar booking allows Leveraging Race Conditions.This issue affects Booking Calendar: from n/a through 11.8.4.

Affected products

  • Wpdevelop Booking Calendar: up to and including 11.8.4

Published 2026-10-02. Last modified 2026-10-05.