A vulnerability was found in Appointment Booking and Scheduling Calendar Plugin up to 1.0.36 on WordPress. It has been declared as problematic. Impacted is the function
update/register_routes of the component Booking Details Handler. Such manipulation leads to missing authorization.
This vulnerability is traded as CVE-2025-5919. The attack may be launched remotely. There is no exploit available.