Junglewise Threat Intelligence

CVE-2026-25444: Magepeople WpBookingly missing authorization in access control

CVE-2026-25444 · Severity: medium · CVSS 4.3 · Published 2026-05-26

Vendors: Magepeople inc..

Executive brief

WpBookingly is a WordPress plugin used for managing service bookings and appointments. A security flaw in the plugin's access control settings allows logged-in users with low-level permissions to perform actions they should not be authorized to access. This could lead to unauthorized changes to booking data or plugin configurations, though it does not directly expose sensitive customer data.

Technical details

A Missing Authorization (CWE-862) vulnerability exists in the Magepeople inc. WpBookingly plugin for WordPress through version 1.2.9. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. An attacker authenticated with low-level privileges (such as a Contributor) can exploit this over the network to perform unauthorized actions. The vulnerability is resolved in version 1.3.0.

Affected products

  • Magepeople inc. WpBookingly n/a through 1.2.9

Timeline

  • 2025-12-22: other: Reported by researcher johska
  • 2026-05-26: disclosed: Early warning sent to Patchstack customers
  • 2026-05-26: advisory: Published by Patchstack and NVD
  • 2026-05-26: patched: Fixed in version 1.3.0

References