
CVE-2026-6810 The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the dex_bccf_a… https://www.cve.org/CVERecord?id=CVE-2026-6810
Post summary
The Booking Calendar Contact Form plugin for WordPress is disclosed to have an Insecure Direct Object Reference (IDOR) vulnerability in all versions up to 1.2.63, with a CVE record linked for further details.
