← WordPress Vulnerabilities
WordPress security by component

Pinpoint Booking System

Pinpoint Booking System provides calendars, availability management, and reservation tools for creating booking systems in WordPress.

Pinpoint Booking System (booking-system) is a WordPress plugin with 13 published CVE records in this archive. The latest tracked vulnerability was published Aug 15, 2026; the highest published CVSS base score is 8.8.

Plugin slug: booking-system

CVE-2026-12128: Pinpoint Booking cart_data permits unauthenticated WooCommerce price manipulation

Pinpoint Booking System through 2.9.9.6.8 exposes dopbsp_woocommerce_add_to_cart through wp_ajax_nopriv without authentication or a nonce. The update handler trusts price_total from the cart_data POST value and stores it directly; woocommerce_before_calculate_totals later reads that value and calls set_price() without recalculating from calendar settings. An unauthenticated buyer can therefore purchase a calendar-linked product at an arbitrary chosen price. Other cart_data fields are not disclosed.

PublishedAug 15, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for booking-system
Safe version
Aug 15, 2026 CVE-2026-12128
Pinpoint Booking cart_data permits unauthenticated WooCommerce price manipulation
Pinpoint Booking System through 2.9.9.6.8 exposes dopbsp_woocommerce_add_to_cart through wp_ajax_nopriv without authentication or a nonce. The update handler trusts price_total from the cart_data POST value and stores it directly; woocommerce_before_calculate_totals later reads that value and calls set_price() without recalculating from calendar settings. An unauthenticated buyer can therefore purchase a calendar-linked product at an arbitrary chosen price. Other cart_data fields are not disclosed.
See mitigation notes
CVE5.3
NVDPending
Aug 10, 2026 CVE-2026-15229
Pinpoint Booking System accepts attacker-chosen booking prices
Pinpoint Booking System through 2.9.9.6.9 trusts a client-supplied booking price instead of recalculating it on the server. An unauthenticated customer can submit an arbitrary or zero price and, with an advisory-described payment method whose exact identity is not disclosed, have the booking immediately approved.
> 2.9.9.6.9
CVE5.3
NVDPending
Aug 01, 2026 CVE-2026-15403
Pinpoint Booking System field filtering permits administrator SQL injection
Pinpoint Booking System – Version 2 through 2.9.9.6.9 inserts the administrator-controlled field parameter into a database query without sufficient escaping or query preparation. An Administrator can obtain the required nonce from any plugin administration page loaded under manage_options, submit crafted SQL through field, and use the resulting blind SQL-injection behavior to infer or extract information available to the WordPress database account. The published.
See mitigation notes
CVE4.9
NVDPending
Apr 08, 2026 CVE-2026-39678
Pinpoint Booking System: A security weakness
Pinpoint Booking System is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.9.9.6.5.
See mitigation notes
CVE5.3
NVDPending
Dec 13, 2024 CVE-2024-54252
Pinpoint Booking System: A security weakness
Pinpoint Booking System is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.3
NVDPending
Dec 06, 2024 CVE-2024-53815
Pinpoint Booking System: SQL injection
Pinpoint Booking System is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVDPending
Oct 17, 2024 CVE-2024-49304
Pinpoint Booking System: Cross-site scripting
Pinpoint Booking System is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Sep 07, 2024 CVE-2024-7112
Pinpoint Booking System – #1 WordPress Booking Plugin: SQL injection
Pinpoint Booking System – #1 WordPress Booking Plugin is affected by SQL injection. Exploitation requires an authenticated subscriber account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD6.5
Jun 04, 2024 CVE-2023-38520
Pinpoint Booking System: A security weakness
Pinpoint Booking System is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Oct 13, 2023 CVE-2023-45270
Booking System: Cross-site request forgery
Booking System is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Apr 06, 2023 CVE-2023-25062
Booking System: Cross-site scripting
Booking System is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Oct 10, 2019 CVE-2015-9460
Booking System: SQL injection
Booking System is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVEPending
NVD8.8
May 22, 2014 CVE-2014-3210
Booking System: SQL injection
Booking System is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVEPending
NVD6.5