Executive brief
EduAdmin Booking is a WordPress plugin for managing course bookings and registrations. A critical authentication flaw in versions up to 5.4.2 allows attackers to log in without credentials or impersonate other users, giving them full access to booking data, student information, and administrative functions without needing valid passwords.
Technical details
The vulnerability is a broken authentication issue (OWASP A7) in EduAdmin Booking versions 5.4.2 and earlier that allows unauthenticated attackers to bypass login controls. An attacker can either circumvent the login mechanism entirely or log in as arbitrary users without possessing their credentials. The flaw requires no authentication, no user interaction, and is network-accessible via HTTP requests to the plugin's authentication endpoints. Successful exploitation grants full administrative and booking system access, including sensitive student data and financial information. The vulnerability was patched in version 6.0.0; users should update immediately.
Affected products
- MultiNet Interactive AB EduAdmin Booking 5.4.2 and earlier
Timeline
- 2026-09-15: disclosed: Published to Patchstack database
- 2026-09-15: patched: Patched in version 6.0.0
- 2026-09-17: advisory: CVE-2026-62101 published