Pinpoint Booking System
Pinpoint Booking System provides calendars, availability management, and reservation tools for creating booking systems in WordPress.
Pinpoint Booking System (booking-system) is a WordPress plugin with 13 published CVE records in this archive. The latest tracked vulnerability was published Aug 15, 2026; the highest published CVSS base score is 8.8.
booking-systemCVE-2026-12128: Pinpoint Booking cart_data permits unauthenticated WooCommerce price manipulation
Pinpoint Booking System through 2.9.9.6.8 exposes dopbsp_woocommerce_add_to_cart through wp_ajax_nopriv without authentication or a nonce. The update handler trusts price_total from the cart_data POST value and stores it directly; woocommerce_before_calculate_totals later reads that value and calls set_price() without recalculating from calendar settings. An unauthenticated buyer can therefore purchase a calendar-linked product at an arbitrary chosen price. Other cart_data fields are not disclosed.
| Safe version |
|
||
|---|---|---|---|
| Aug 15, 2026 |
CVE-2026-12128
Pinpoint Booking cart_data permits unauthenticated WooCommerce price manipulation
Pinpoint Booking System through 2.9.9.6.8 exposes dopbsp_woocommerce_add_to_cart through wp_ajax_nopriv without authentication or a nonce. The update handler trusts price_total from the cart_data POST value and stores it directly; woocommerce_before_calculate_totals later reads that value and calls set_price() without recalculating from calendar settings. An unauthenticated buyer can therefore purchase a calendar-linked product at an arbitrary chosen price. Other cart_data fields are not disclosed.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Aug 10, 2026 |
CVE-2026-15229
Pinpoint Booking System accepts attacker-chosen booking prices
Pinpoint Booking System through 2.9.9.6.9 trusts a client-supplied booking price instead of recalculating it on the server. An unauthenticated customer can submit an arbitrary or zero price and, with an advisory-described payment method whose exact identity is not disclosed, have the booking immediately approved.
|
> 2.9.9.6.9 |
CVE5.3
NVDPending
|
| Aug 01, 2026 |
CVE-2026-15403
Pinpoint Booking System field filtering permits administrator SQL injection
Pinpoint Booking System – Version 2 through 2.9.9.6.9 inserts the administrator-controlled field parameter into a database query without sufficient escaping or query preparation. An Administrator can obtain the required nonce from any plugin administration page loaded under manage_options, submit crafted SQL through field, and use the resulting blind SQL-injection behavior to infer or extract information available to the WordPress database account. The published.
|
See mitigation notes |
CVE4.9
NVDPending
|
| Apr 08, 2026 |
CVE-2026-39678
Pinpoint Booking System: A security weakness
Pinpoint Booking System is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.9.9.6.5.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Dec 13, 2024 |
CVE-2024-54252
Pinpoint Booking System: A security weakness
Pinpoint Booking System is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.3
NVDPending
|
| Dec 06, 2024 |
CVE-2024-53815
Pinpoint Booking System: SQL injection
Pinpoint Booking System is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVDPending
|
| Oct 17, 2024 |
CVE-2024-49304
Pinpoint Booking System: Cross-site scripting
Pinpoint Booking System is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Sep 07, 2024 |
CVE-2024-7112
Pinpoint Booking System – #1 WordPress Booking Plugin: SQL injection
Pinpoint Booking System – #1 WordPress Booking Plugin is affected by SQL injection. Exploitation requires an authenticated subscriber account. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVD6.5
|
| Jun 04, 2024 |
CVE-2023-38520
Pinpoint Booking System: A security weakness
Pinpoint Booking System is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Oct 13, 2023 |
CVE-2023-45270
Booking System: Cross-site request forgery
Booking System is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Apr 06, 2023 |
CVE-2023-25062
Booking System: Cross-site scripting
Booking System is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Oct 10, 2019 |
CVE-2015-9460
Booking System: SQL injection
Booking System is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD8.8
|
| May 22, 2014 |
CVE-2014-3210
Booking System: SQL injection
Booking System is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD6.5
|