CVE-2026-73395: Wpdevart Booking Calendar, Appointment Booking System

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions.

Affected products

  • Wpdevart Booking Calendar, Appointment Booking System: up to and including 3.2.36

Published 2026-08-18. Last modified 2026-08-20.