๐Ÿ” CVE Alert

CVE-2026-16986

MEDIUM 5.3

Booking Package < 1.7.25 - Unauthenticated Price Manipulation via Service and Option Cost Parameters

CVSS Score
5.3
EPSS Score
0.2%
EPSS Percentile
7th

The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored service price, deriving the expected charge from attacker-supplied request values instead, so an unauthenticated attacker can pay an arbitrary fraction of a service's real price.

Vendor unknown
Product booking package
Published Aug 26, 2026
Last Updated Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for unknown booking package

Be the first to know when new medium vulnerabilities affecting unknown booking package are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Booking Package
0 < 1.7.25

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/8df11bf9-1878-4220-b13c-82e8dadc3a08/

Credits

Muni Nitish Kumar Yaddala WPScan