Executive brief
The Pinpoint Booking System – Version 2 plugin for WordPress allows customers to manipulate product prices during checkout without authentication. An attacker can override the cost of any bookable product to an arbitrary value (such as $0.01), effectively purchasing any inventory at self-chosen prices. This directly impacts revenue and exposes e-commerce sites to fraud and order manipulation.
Technical details
The vulnerability is a price manipulation flaw in the WooCommerce integration of the Pinpoint Booking System plugin. The `dopbsp_woocommerce_add_to_cart` AJAX action is registered via `wp_ajax_nopriv_*` with no authentication, nonce verification, or server-side price validation. The vulnerable code reads `price_total` directly from the attacker-controlled `cart_data` POST parameter, persists it to the database without validation, and later retrieves and applies this value to product pricing via `set_price()` without recalculating from calendar settings. An unauthenticated attacker can send a crafted AJAX request with a malicious `cart_data` parameter to override checkout prices for any bookable product tied to a booking calendar, enabling purchase of products at any attacker-chosen price.
Affected products
- Pinpoint Booking System – Version 2 up to and including 2.9.9.6.8
Timeline
- 2026-08-15: disclosed