CVE-2026-76586
7.5WordPress · Appointment Booking Calendar Plugin and Scheduling Plugin
An improper access control flaw in the Appointment Booking Calendar WordPress plugin allows unauthenticated users to manipulate payment verification, resulting in unauthorized appointment approval.
Executive summary
The Appointment Booking Calendar Plugin for WordPress contains an unauthenticated access control vulnerability that permits users to bypass payment verification for bookings.
Vulnerability
The plugin fails to perform server-side validation of payment amounts during the booking confirmation process. This allows an unauthenticated attacker to manipulate payment data to secure appointments at a fraction of the intended cost.
Business impact
Successful exploitation of this vulnerability leads to a direct loss of revenue and integrity for business scheduling systems. With a CVSS score of 7.5, the risk is high because it facilitates unauthorized service access without requiring any user credentials, potentially leading to significant operational and financial disruption for organizations relying on the plugin for paid services.
Remediation
Immediate Action: Update the Appointment Booking Calendar Plugin and Scheduling Plugin to version 1.6.3 or later to enforce proper server-side payment verification.
Proactive Monitoring: Review booking logs and payment confirmation records for suspicious transactions where the payment amount does not match the expected service price.
Compensating Controls: Deploy a Web Application Firewall (WAF) to monitor and block abnormal HTTP traffic patterns directed at the booking confirmation endpoint.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations using this plugin must prioritize the update to version 1.6.3 immediately to close the payment verification gap. Failure to patch this vulnerability leaves the business exposed to direct financial manipulation and unauthorized service consumption by unauthenticated actors.
More WordPress CVEs
Sources
Originally found and disclosed by Nguyen Phuoc Thinh - HPT Vietnam Corporation, with WPScan (coordinator), per the CVE Program record.