PT-2026-64853 · WordPress · Bookingpress Appointment Booking Pro
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
bookingpress-appointment-booking-pro versions prior to 5.7.3
Description
The plugin fails to correctly invoke its REST permission callback, which results in all routes within one of its API namespaces being accessible without authentication. This allows unauthenticated attackers to access sensitive customer booking data and modify bookings belonging to other users.
Recommendations
Update bookingpress-appointment-booking-pro to version 5.7.3 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bookingpress Appointment Booking Pro