What is CVE-2026-27377?
A Broken Access Control vulnerability has been found in the Booking Agent role of the QuickCal - Appointment Booking Calendar plugin for WordPress (<=1.0.16). This allows agents to perform unauthorized actions. It is recommended to update the plugin to the latest version.
Azərbaycanca: WordPress üçün QuickCal plaginində (<=1.0.16) Booking Agent rolu üçün 'Broken Access Control' zəifliyi aşkar edilib. Bu, agentlərin icazəsiz hərəkətlər etməsinə imkan yaradır. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the QuickCal plugin are affected by CVE-2026-27377?
CVE-2026-27377 affects the QuickCal - Appointment Booking Calendar plugin for WordPress versions 1.0.16 and earlier.
How can users protect against CVE-2026-27377?
To protect against CVE-2026-27377, it is recommended to update the QuickCal plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.