Junglewise Threat Intelligence

CVE-2026-12128: Pinpoint Booking System , Version 2 price manipulation in WooCommerce cart

CVE-2026-12128 · Severity: medium · CVSS 5.3 · Published 2026-08-15

Executive brief

The Pinpoint Booking System – Version 2 plugin for WordPress allows customers to manipulate product prices during checkout without authentication. An attacker can override the cost of any bookable product to an arbitrary value (such as $0.01), effectively purchasing any inventory at self-chosen prices. This directly impacts revenue and exposes e-commerce sites to fraud and order manipulation.

Technical details

The vulnerability is a price manipulation flaw in the WooCommerce integration of the Pinpoint Booking System plugin. The `dopbsp_woocommerce_add_to_cart` AJAX action is registered via `wp_ajax_nopriv_*` with no authentication, nonce verification, or server-side price validation. The vulnerable code reads `price_total` directly from the attacker-controlled `cart_data` POST parameter, persists it to the database without validation, and later retrieves and applies this value to product pricing via `set_price()` without recalculating from calendar settings. An unauthenticated attacker can send a crafted AJAX request with a malicious `cart_data` parameter to override checkout prices for any bookable product tied to a booking calendar, enabling purchase of products at any attacker-chosen price.

Affected products

  • Pinpoint Booking System – Version 2 up to and including 2.9.9.6.8

Timeline

  • 2026-08-15: disclosed

References