PT-2026-39954 · Zealopensource+1 · Smart Appointment & Booking
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Smart Appointment & Booking versions prior to 1.0.9
Description
Unauthorized modification of data is possible due to a missing capability check and a nonce validation logic flaw in the
saab cancel booking() function. The nonce check incorrectly uses the && (AND) operator instead of || (OR), allowing the security check to be bypassed if any value is provided for the security parameter. This enables unauthenticated attackers to cancel arbitrary bookings by providing a predictable booking ID.Recommendations
Update the plugin to version 1.0.9 or later.
As a temporary workaround, restrict access to the
saab cancel booking() function until the update is applied.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smart Appointment & Booking