← Zurück zur CVE-Suche

CVE-2026-9830

bookingpress-appointment-booking-pro

Beschreibung

The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users- bookings.

CVSS 8.2EPSS 0.248%Risiko 0.84
Quelle öffnen
Veröffentlicht
2026-07-27 07:16:30
Betroffene Versionen
<5.7.3
Typ
Webanwendung
Zuletzt geändert
2026-07-27 20:33:01
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N