CVE-2026-9830
BookingPress · BookingPress Appointment Booking Pro
The BookingPress Appointment Booking Pro WordPress plugin is vulnerable to improper authentication, allowing unauthenticated attackers to potentially bypass security controls.
Executive summary
An authentication bypass vulnerability in BookingPress Appointment Booking Pro exposes WordPress sites to unauthorized access and potential data manipulation.
Vulnerability
This vulnerability involves improper authentication (CWE-287), which allows an unauthenticated attacker to interact with the plugin's functionality without valid credentials. The CVSS vector confirms that no user interaction or high privileges are required to exploit this flaw.
Business impact
The ability for an unauthenticated attacker to bypass authentication mechanisms could lead to unauthorized access to booking data, sensitive customer information, and potential modification of appointment records. With a CVSS score of 8.2, this vulnerability represents a high risk to both system integrity and customer privacy.
Remediation
Immediate Action: Update the BookingPress Appointment Booking Pro plugin to version 5.7.3 or later immediately.
Proactive Monitoring: Review audit logs for unexpected account access or unauthorized modifications to appointment data.
Compensating Controls: Implement strict access control lists at the network level and utilize a WAF to filter malicious traffic attempting to interact with plugin-specific endpoints.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exists in a GitHub repository (ChPratik/CVE-2026-9830).
Analyst recommendation
Due to the existence of a public proof-of-concept and the high severity of this authentication flaw, administrators must ensure the plugin is updated to version 5.7.3 or later without delay. Failure to patch may result in unauthorized access to sensitive appointment management systems.