Junglewise Threat Intelligence

CVE-2026-40780: StellarWP BookIt authentication bypass in password recovery

CVE-2026-40780 · Severity: high · CVSS 7.5 · Published 2026-06-02

Vendors: StellarWP.

Executive brief

The BookIt plugin for WordPress, used for managing appointments and bookings, contains a security flaw in its authentication system. An unauthorized attacker could exploit this vulnerability to bypass security checks during the password recovery process. This could allow an attacker to gain administrative access to the website, potentially leading to full site takeover and data exposure.

Technical details

An Authentication Bypass Using an Alternate Path or Channel (CWE-288) exists in the StellarWP BookIt plugin for WordPress. The vulnerability resides in the password recovery logic, where insufficient validation allows an attacker to bypass standard authentication requirements. This is an unauthenticated, network-reachable attack with low complexity. Successful exploitation allows a malicious actor to manipulate the password reset process to gain access to accounts, including those with high privileges. The issue is addressed in version 2.5.4.1.

Affected products

  • StellarWP / Liquid Web BookIt up to 2.5.1

Timeline

  • 2026-03-11: other: Vulnerability reported by researcher
  • 2026-04-22: advisory: Patchstack advisory published
  • 2026-06-02: disclosed: CVE published to NVD

References

Related threats