WordPress security by component
BookingPress Appointment Booking Pro
Plugin description
BookingPress Appointment Booking Pro is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 8.2.
Plugin slug:
bookingpress-appointment-booking-proLatest vulnerability
CVE-2026-9830: BookingPress Pro REST routes expose and alter customer bookings
BookingPress Appointment Booking Pro before 5.7.3 fails to invoke the permission callback correctly for every route in one REST API namespace. An unauthenticated attacker can therefore reach those routes without a WordPress account, read customer booking data and modify bookings belonging to other users. The CNA record does not identify the affected namespace, route names, request parameters or callback function.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-9830
BookingPress Pro REST routes expose and alter customer bookings
BookingPress Appointment Booking Pro before 5.7.3 fails to invoke the permission callback correctly for every route in one REST API namespace. An unauthenticated attacker can therefore reach those routes without a WordPress account, read customer booking data and modify bookings belonging to other users. The CNA record does not identify the affected namespace, route names, request parameters or callback function.
|
5.7.3 |
CVE8.2
NVDPending
|
| Jul 01, 2026 |
CVE-2026-11823
BookingPress Appointment Booking Pro: SQL injection
BookingPress Appointment Booking Pro is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 5.7.1.
|
> 5.7.1 |
CVE7.5
NVDPending
|