Junglewise Threat Intelligence

CVE-2026-57746: ThemeREX Booked broken access control in WordPress plugin

CVE-2026-57746 · Severity: high · CVSS 7.1 · Published 2026-07-02

Vendors: ThemeREX.

Executive brief

The Booked plugin for WordPress, which is used for managing appointments and bookings, contains a security flaw that allows users with basic 'Subscriber' accounts to bypass access restrictions. An attacker with a low-level account could potentially view sensitive information or perform actions they are not authorized to do. This could lead to the exposure of customer booking data or disruption of the appointment system.

Technical details

A broken access control vulnerability exists in the ThemeREX Booked plugin for WordPress (versions up to and including 3.0.0) due to missing authorization checks (CWE-862). An authenticated attacker with Subscriber-level privileges can exploit this flaw via network requests to execute functions or access data intended for higher-privileged users. The vulnerability has a CVSS 3.1 base score of 7.1, reflecting high confidentiality impact. As of the advisory date, no official patch has been released, and users are advised to monitor for updates or use third-party mitigation rules.

Affected products

  • ThemeREX Booked <= 3.0.0

Timeline

  • 2026-02-01: other: Reported by researcher Phat RiO
  • 2026-07-02: disclosed: Vulnerability published by Patchstack
  • 2026-07-02: advisory: CVE-2026-57746 published to NVD

References

Related threats