← Volver al buscador de CVEs

CVE-2026-9830

bookingpress-appointment-booking-pro

Descripción

The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users- bookings.

CVSS 8.2EPSS 0.248%Riesgo 0.84
Ver fuente
Publicación
2026-07-27 07:16:30
Versiones afectadas
<5.7.3
Tipo
Aplicación web
Última modificación
2026-07-27 20:33:01
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N