CVE-2026-9830

BookingPress · BookingPress Appointment Booking Pro

The BookingPress Appointment Booking Pro WordPress plugin is vulnerable to improper authentication, allowing unauthenticated attackers to potentially bypass security controls.

Executive summary

An authentication bypass vulnerability in BookingPress Appointment Booking Pro exposes WordPress sites to unauthorized access and potential data manipulation.

Vulnerability

This vulnerability involves improper authentication (CWE-287), which allows an unauthenticated attacker to interact with the plugin's functionality without valid credentials. The CVSS vector confirms that no user interaction or high privileges are required to exploit this flaw.

Business impact

The ability for an unauthenticated attacker to bypass authentication mechanisms could lead to unauthorized access to booking data, sensitive customer information, and potential modification of appointment records. With a CVSS score of 8.2, this vulnerability represents a high risk to both system integrity and customer privacy.

Remediation

Immediate Action: Update the BookingPress Appointment Booking Pro plugin to version 5.7.3 or later immediately.

Proactive Monitoring: Review audit logs for unexpected account access or unauthorized modifications to appointment data.

Compensating Controls: Implement strict access control lists at the network level and utilize a WAF to filter malicious traffic attempting to interact with plugin-specific endpoints.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exists in a GitHub repository (ChPratik/CVE-2026-9830).

Analyst recommendation

Due to the existence of a public proof-of-concept and the high severity of this authentication flaw, administrators must ensure the plugin is updated to version 5.7.3 or later without delay. Failure to patch may result in unauthorized access to sensitive appointment management systems.