CVE-2026-16986 PUBLISHED

Booking Package < 1.7.25 - Unauthenticated Price Manipulation via Service and Option Cost Parameters

Assigner: WPScan
Reserved: 24.07.2026 Published: 26.08.2026 Updated: 26.08.2026

The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored service price, deriving the expected charge from attacker-supplied request values instead, so an unauthenticated attacker can pay an arbitrary fraction of a service's real price.

Product Status

Vendor Unknown
Product Booking Package
Versions Default: unaffected
  • affected from 0 to 1.7.25 (excl.)

Credits

  • Muni Nitish Kumar Yaddala finder
  • WPScan coordinator

References

Problem Types

  • CWE-284 Improper Access Control CWE