Junglewise Threat Intelligence

CVE-2026-57747: ThemeREX Booked CSRF in WordPress plugin

CVE-2026-57747 · Severity: medium · CVSS 6.5 · Published 2026-07-02

Vendors: ThemeREX.

Executive brief

The Booked plugin for WordPress, which is used for managing appointments and bookings, contains a security flaw that could allow an attacker to trick an administrator into performing unintended actions. By getting a logged-in user to click a malicious link, an attacker could potentially disrupt the booking service or change settings without authorization. This could lead to service outages or unauthorized modifications to the appointment system.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the ThemeREX Booked plugin for WordPress through version 3.0.0. The flaw is rooted in a lack of proper nonce validation or equivalent CSRF protections on sensitive administrative functions. An unauthenticated remote attacker can exploit this by crafting a malicious webpage or link and inducing a logged-in administrator to interact with it. Successful exploitation allows the attacker to execute actions on behalf of the authenticated user, which, according to the CVSS vector, primarily impacts the availability of the service. As of the advisory date, no official patch has been released.

Affected products

  • ThemeREX Booked <= 3.0.0

Timeline

  • 2026-02-01: other: Reported by researcher Phat RiO
  • 2026-07-02: disclosed: Vulnerability published by Patchstack
  • 2026-07-02: advisory: CVE-2026-57747 assigned

References

Related threats