PT-2026-64853 · WordPress · Bookingpress Appointment Booking Pro

·

CVE-2026-9830

·

Published

2026-07-27

·

Updated

2026-07-27

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions bookingpress-appointment-booking-pro versions prior to 5.7.3
Description The plugin fails to correctly invoke its REST permission callback, which results in all routes within one of its API namespaces being accessible without authentication. This allows unauthenticated attackers to access sensitive customer booking data and modify bookings belonging to other users.
Recommendations Update bookingpress-appointment-booking-pro to version 5.7.3 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9830

Affected Products

Bookingpress Appointment Booking Pro