Executive brief
The Booking Package plugin for WordPress, which provides appointment and reservation management, contains a security flaw that allows unauthorized users to perform restricted actions. An attacker could exploit this to modify settings or data without needing a password or administrative account. This could lead to unauthorized changes in booking schedules or service configurations, potentially disrupting business operations.
Technical details
A broken access control vulnerability (CWE-862) exists in the Booking Package plugin for WordPress in versions up to and including 1.7.06. The flaw stems from missing authorization or nonce checks in certain functions, allowing an unauthenticated remote attacker to execute privileged actions. According to the CVSS vector, the impact is primarily on integrity, suggesting that an attacker can modify data but not necessarily view sensitive information or crash the service. The issue is resolved in version 1.7.07.
Affected products
- SAKURA Internet Booking Package <= 1.7.06
Timeline
- 2026-03-09: other: Reported by researcher Skoobi
- 2026-04-21: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date