← WordPress Vulnerabilities
WordPress security by component

BookingPress Appointment Booking Pro

BookingPress Appointment Booking Pro is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 8.2.

Plugin slug: bookingpress-appointment-booking-pro

CVE-2026-9830: BookingPress Pro REST routes expose and alter customer bookings

BookingPress Appointment Booking Pro before 5.7.3 fails to invoke the permission callback correctly for every route in one REST API namespace. An unauthenticated attacker can therefore reach those routes without a WordPress account, read customer booking data and modify bookings belonging to other users. The CNA record does not identify the affected namespace, route names, request parameters or callback function.

PublishedJul 27, 2026
Known safe version5.7.3
Safe version
Jul 27, 2026 CVE-2026-9830
BookingPress Pro REST routes expose and alter customer bookings
BookingPress Appointment Booking Pro before 5.7.3 fails to invoke the permission callback correctly for every route in one REST API namespace. An unauthenticated attacker can therefore reach those routes without a WordPress account, read customer booking data and modify bookings belonging to other users. The CNA record does not identify the affected namespace, route names, request parameters or callback function.
5.7.3
CVE8.2
NVDPending
Jul 01, 2026 CVE-2026-11823
BookingPress Appointment Booking Pro: SQL injection
BookingPress Appointment Booking Pro is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 5.7.1.
> 5.7.1
CVE7.5
NVDPending