CVE-2026-9830 PUBLISHED

BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug

Assigner: WPScan
Reserved: 28.05.2026 Published: 27.07.2026 Updated: 27.07.2026

The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.

Product Status

Vendor Unknown
Product bookingpress-appointment-booking-pro
Versions Default: unaffected
  • affected from 0 to 5.7.3 (excl.)

Credits

  • Kolja Zuelsdorf finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE