Junglewise Threat Intelligence

CVE-2026-39525: Booking Activities WordPress plugin broken access control

CVE-2026-39525 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Executive brief

The Booking Activities plugin for WordPress, which manages appointment and activity scheduling, contains a security flaw that allows unauthorized users to perform actions they should not be able to. An attacker could potentially modify booking data or disrupt scheduling operations without needing a password. This could lead to unauthorized changes in business appointments and operational disruptions.

Technical details

A broken access control vulnerability exists in the Booking Activities plugin for WordPress due to missing authorization checks (CWE-862). The flaw allows an unauthenticated remote attacker to execute functions or actions that should be restricted to higher-privileged users. The vulnerability is exploitable over the network without user interaction. Attackers can potentially modify data or impact the availability of the booking system. The issue is resolved in version 1.17.0.

Affected products

  • Booking Activities Booking Activities <= 1.16.48.1

Timeline

  • 2026-01-27: other: Reported by Nguyen Ba Khanh
  • 2026-04-13: disclosed: Initial disclosure by Patchstack
  • 2026-04-13: patched: Version 1.17.0 released
  • 2026-06-15: advisory: NVD published date

References