Back to overview

CVE-2026-9830

Description
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.

Metadata

CVE ID
CVE-2026-9830
State
PUBLISHED
Assigner
WPScan
Reserved
2026-05-28 12:10 UTC
Published
2026-07-27 06:00 UTC
Last updated
2026-07-27 06:00 UTC
Vendor / Product
Unknown / bookingpress-appointment-booking-pro
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Unknown bookingpress-appointment-booking-pro 0 < 5.7.3
Weakness (CWE)
CWESourceDescription
cna CWE-287 Improper Authentication
Back to overview