Junglewise Threat Intelligence

CVE-2026-27409: Webba Plugins Webba Booking missing authorization

CVE-2026-27409 · Severity: medium · CVSS 5.3 · Published 2026-07-01

Executive brief

Webba Booking is a WordPress plugin used to manage online appointments and reservations. A security flaw in the plugin's access control settings allows unauthorized individuals to perform actions that should be restricted to administrators or specific staff. This could lead to unauthorized changes in booking configurations or data, potentially disrupting business operations and scheduling.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Webba Booking plugin for WordPress through version 6.4.13. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. An unauthenticated remote attacker can exploit this lack of enforcement to perform unauthorized actions or modify settings. The vulnerability is addressed in version 6.4.14.

Affected products

  • Webba Plugins Webba Booking n/a through 6.4.13

Timeline

  • 2025-11-05: other: Reported by Legion Hunter
  • 2026-07-01: disclosed: Early warning sent to Patchstack customers
  • 2026-07-01: patched: Version 6.4.14 released
  • 2026-07-01: advisory: Public advisory published by Patchstack and NVD

References