Junglewise Threat Intelligence

CVE-2026-5693: ZealousWeb Smart Appointment & Booking unauthorized booking cancellation

CVE-2026-5693 · Severity: medium · CVSS 5.3 · Published 2026-05-12

Executive brief

The Smart Appointment & Booking plugin for WordPress, used to manage customer schedules, contains a security flaw that allows unauthorized individuals to cancel appointments. By exploiting a logic error in how the plugin verifies requests, an attacker can delete any booking without needing to log in. This could lead to significant operational disruption and loss of customer trust for businesses relying on the plugin for their scheduling.

Technical details

The vulnerability exists in the saab_cancel_booking() function within the Smart Appointment & Booking plugin for WordPress (versions up to 1.0.8). The root cause is a combination of missing capability checks and a logic error in nonce validation where the code uses an 'AND' (&&) operator instead of an 'OR' (||) operator. This flaw allows the security check to be bypassed if any value is provided for the security parameter. An unauthenticated remote attacker can exploit this by sending a request with a predictable booking ID to cancel arbitrary appointments. The plugin has been temporarily closed on the WordPress repository pending review.

Affected products

  • ZealousWeb Smart Appointment & Booking Up to, and including, 1.0.8

Timeline

  • 2026-05-06: other: Plugin temporarily closed on WordPress.org repository
  • 2026-05-12: disclosed: Vulnerability published by Wordfence and NVD

References