CVE-2026-9830
BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.
| Vendor | unknown |
| Product | bookingpress-appointment-booking-pro |
| Published | Jul 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown bookingpress-appointment-booking-pro
Be the first to know when new unknown vulnerabilities affecting unknown bookingpress-appointment-booking-pro are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / bookingpress-appointment-booking-pro
0 < 5.7.3
References
Credits
Kolja Zuelsdorf WPScan