CVE-2026-14831
Received Received - Intake

Unauthenticated Minimum Booking Bypass in Easy Booking WordPress Plugin

Vulnerability report for CVE-2026-14831, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WPScan

Description

The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking duration on the server side when adding to cart and calculating the booking price, allowing unauthenticated users to place below-minimum bookings and complete underpriced orders.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
easy_booking easy_booking to 3.5.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Easy Booking WordPress plugin before version 3.5.0. It fails to enforce the minimum booking duration set for a product on the server side during checkout. This allows unauthenticated users to add items to the cart and complete orders even if the booking duration is below the configured minimum, resulting in underpriced orders.

Impact Analysis

Unauthenticated users could exploit this to place bookings that violate minimum duration requirements, leading to financial losses from underpriced orders. Businesses using the plugin may face incorrect pricing, potential disputes, and loss of revenue due to improper order calculations.

Mitigation Strategies

Update the Easy Booking WordPress plugin to version 3.5.0 or later to address the server-side validation issue for minimum booking duration and pricing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14831. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart