Junglewise Threat Intelligence

CVE-2026-25439: fs-code Booknetic authentication bypass in WordPress plugin

CVE-2026-25439 · Severity: high · CVSS 8.1 · Published 2026-06-17

Executive brief

Booknetic is a popular appointment booking plugin for WordPress websites. A security flaw in the plugin's authentication system allows unauthorized individuals to bypass login requirements. If exploited, an attacker could gain administrative access to the website, potentially leading to full site takeover, data theft, or service disruption.

Technical details

A broken authentication vulnerability (CWE-288) exists in the Booknetic plugin for WordPress through version 4.8.5. The flaw allows an unauthenticated attacker to bypass authentication mechanisms via an alternate path or channel. Successful exploitation can lead to full account takeover, including administrative accounts. While the attack vector is network-based and requires no user interaction, the CVSS complexity is rated as high. As of the advisory date, no official patch is available from the developer, though third-party mitigation rules have been released.

Affected products

  • fs-code Booknetic <= 4.8.5

Timeline

  • 2025-12-24: other: Vulnerability reported by researcher Phat RiO
  • 2026-06-01: advisory: Patchstack published advisory and mitigation rules
  • 2026-06-17: disclosed: CVE published to NVD

References