๐Ÿ” CVE Alert

CVE-2026-76586

UNKNOWN 0.0

BookingPress 1.5.6 - 1.6.2 - Unauthenticated Booking Price Manipulation via PayPal Payment Confirmation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price.

Vendor unknown
Product appointment booking calendar plugin and scheduling plugin
Published Aug 29, 2026
Stay Ahead of the Next One

Get instant alerts for unknown appointment booking calendar plugin and scheduling plugin

Be the first to know when new unknown vulnerabilities affecting unknown appointment booking calendar plugin and scheduling plugin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Appointment Booking Calendar Plugin and Scheduling Plugin
1.5.6 < 1.6.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/bc74bc9b-92ce-434e-a21d-34d7525c8600/

Credits

Nguyen Phuoc Thinh - HPT Vietnam Corporation WPScan