A vulnerability was found in Booking Calendar Plugin up to 10.14.13 on WordPress. It has been rated as problematic. The affected element is the function wpbc_ajax_WPBC_FLEXTIMELINE_NAV. This manipulation causes missing authorization.

This vulnerability is registered as CVE-2026-1431. Remote exploitation of the attack is possible. No exploit is available.