CVE-2026-15229 PUBLISHED

Pinpoint Booking System <= 2.9.9.6.9 - Unauthenticated Arbitrary Booking Price Manipulation

Assigner: WPScan
Reserved: 09.07.2026 Published: 10.08.2026 Updated: 10.08.2026

The Pinpoint Booking System WordPress plugin through 2.9.9.6.9 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation.

Product Status

Vendor Unknown
Product Pinpoint Booking System
Versions Default: unknown
  • affected from 0 to 2.9.9.6.9 (incl.)

Credits

  • Ahmed Hashim Ismael finder
  • WPScan coordinator

References

Problem Types

  • CWE-863 Incorrect Authorization CWE