PT-2026-81949 · WordPress · Booking Package
CVE-2026-16986
·
Published
2026-08-26
·
Updated
2026-08-26
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Booking Package versions prior to 1.7.25
Description
An issue exists where the plugin fails to validate the payment amount on the server side against the stored service price. Instead, the expected charge is derived from values supplied in the request, allowing an unauthenticated attacker to pay an arbitrary fraction of the actual service price.
Recommendations
Update Booking Package to version 1.7.25 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Booking Package