Executive brief
The Pinpoint Booking System plugin for WordPress, which manages reservations and appointments, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to bypass intended security levels, potentially leading to unauthorized access to booking data or system configurations. While the impact is considered moderate, it could allow attackers to interfere with business operations or view sensitive scheduling information.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the DOTonPAPER Pinpoint Booking System (booking-system) plugin for WordPress. The flaw stems from incorrectly configured access control security levels within the plugin's logic, which fails to properly validate user permissions before granting access to certain functions. An unauthenticated remote attacker can exploit this by sending crafted network requests to the affected WordPress site. Successful exploitation allows the attacker to perform actions or access data that should be restricted to higher-privileged users. As of the advisory date, no official patch has been confirmed for versions up to and including 2.9.9.6.5.
Affected products
- DOTonPAPER Pinpoint Booking System <= 2.9.9.6.5
Timeline
- 2026-01-21: other: Vulnerability reported by researcher Quan Realme
- 2026-02-20: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published to NVD