CVE-2026-76586

7.5

WordPress · Appointment Booking Calendar Plugin and Scheduling Plugin

An improper access control flaw in the Appointment Booking Calendar WordPress plugin allows unauthenticated users to manipulate payment verification, resulting in unauthorized appointment approval.

Executive summary

The Appointment Booking Calendar Plugin for WordPress contains an unauthenticated access control vulnerability that permits users to bypass payment verification for bookings.

Vulnerability

The plugin fails to perform server-side validation of payment amounts during the booking confirmation process. This allows an unauthenticated attacker to manipulate payment data to secure appointments at a fraction of the intended cost.

Business impact

Successful exploitation of this vulnerability leads to a direct loss of revenue and integrity for business scheduling systems. With a CVSS score of 7.5, the risk is high because it facilitates unauthorized service access without requiring any user credentials, potentially leading to significant operational and financial disruption for organizations relying on the plugin for paid services.

Remediation

Immediate Action: Update the Appointment Booking Calendar Plugin and Scheduling Plugin to version 1.6.3 or later to enforce proper server-side payment verification.

Proactive Monitoring: Review booking logs and payment confirmation records for suspicious transactions where the payment amount does not match the expected service price.

Compensating Controls: Deploy a Web Application Firewall (WAF) to monitor and block abnormal HTTP traffic patterns directed at the booking confirmation endpoint.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations using this plugin must prioritize the update to version 1.6.3 immediately to close the payment verification gap. Failure to patch this vulnerability leaves the business exposed to direct financial manipulation and unauthorized service consumption by unauthenticated actors.

More WordPress CVEs

Sources

Originally found and disclosed by Nguyen Phuoc Thinh - HPT Vietnam Corporation, with WPScan (coordinator), per the CVE Program record.