CVE-2026-9830
Received Received - Intake

Unauthenticated Access in BookingPress Appointment Booking Pro

Vulnerability report for CVE-2026-9830, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: WPScan

Description

The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-27
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
bookingpress bookingpress_pro to 5.7.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the BookingPress Pro WordPress plugin before version 5.7.3. It stems from a bug in the plugin's REST permission callback, which fails to properly restrict access. As a result, unauthenticated attackers can exploit this flaw to access and modify customer booking data without needing to log in.

Detection Guidance

Check if unauthenticated requests to the affected endpoints return sensitive data. Use curl to test the /calendar, /appointment/reschedule, and /time endpoints. If they return booking details, PII, or time slot data without authentication, the system is vulnerable.

Impact Analysis

Unauthenticated attackers can read personally identifiable information like names, emails, phone numbers, and booking details. They can also modify existing bookings by rescheduling appointments, which updates records and sends confirmation emails from your domain. Attackers can also enumerate available time slots for services.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized access and potential exposure of personally identifiable information and sensitive booking data. It could lead to non-compliance with data protection requirements, resulting in legal penalties and reputational damage.

Mitigation Strategies

Update BookingPress Pro to version 5.7.3 or later immediately. If updating is not possible, disable the plugin temporarily until a patch is applied. Monitor network traffic for unauthorized access attempts to the vulnerable endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9830. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart