Executive brief
BookingPress Pro, a popular WordPress plugin used for managing appointments and bookings, contains a security flaw that allows unauthorized users to upload files to the website's server. If the booking form is configured to include a signature field, an attacker can upload malicious scripts to take full control of the website. This could lead to the theft of customer data, complete site defacement, or the installation of ransomware.
Technical details
The BookingPress Pro plugin for WordPress (versions up to 5.6) is vulnerable to an unrestricted file upload flaw (CWE-434). The vulnerability exists within the 'bookingpress_validate_submitted_booking_form_func' function, which fails to properly validate the file types of uploaded content. An unauthenticated remote attacker can exploit this by submitting a booking form that includes a signature custom field, allowing them to upload arbitrary files such as PHP scripts. Successful exploitation can lead to Remote Code Execution (RCE) and full server compromise. Users are advised to update to a patched version if available or disable signature custom fields as a temporary mitigation.
Affected products
- BookingPress BookingPress Pro up to, and including, 5.6
Timeline
- 2026-05-21: disclosed: Vulnerability published by Wordfence and NVD.