WordPress · Bookingpress Appointment Booking Pro · CVE-2026-9830
**Name of the Vulnerable Software and Affected Versions**
bookingpress-appointment-booking-pro versions prior to 5.7.3
**Description**
The plugin fails to correctly invoke its REST permission callback, which results in all routes within one of its API namespaces being accessible without authentication. This allows unauthenticated attackers to access sensitive customer booking data and modify bookings belonging to other users.
**Recommendations**
Update bookingpress-appointment-booking-pro to version 5.7.3 or later.