CVE-2026-76586
BookingPress 1.5.6 - 1.6.2 - Unauthenticated Booking Price Manipulation via PayPal Payment Confirmation
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price.
| Vendor | unknown |
| Product | appointment booking calendar plugin and scheduling plugin |
| Published | Aug 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown appointment booking calendar plugin and scheduling plugin
Be the first to know when new unknown vulnerabilities affecting unknown appointment booking calendar plugin and scheduling plugin are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Appointment Booking Calendar Plugin and Scheduling Plugin
1.5.6 < 1.6.3
References
Credits
Nguyen Phuoc Thinh - HPT Vietnam Corporation WPScan