Junglewise Threat Intelligence

CVE-2026-76586: WordPress BookingPress Appointment Booking appointment price manipulation

CVE-2026-76586 · Severity: high · CVSS 7.5 · Published 2026-08-29

Executive brief

BookingPress is a WordPress plugin that lets businesses manage appointment bookings and accept online payments. This vulnerability allows attackers to book paid appointments for a fraction of their actual price by manipulating payment confirmation, effectively stealing services or causing significant revenue loss.

Technical details

The plugin fails to validate the payment amount received against the server-side price configured for a booking when confirming PayPal payments. This is a broken access control vulnerability (CWE-284) that allows unauthenticated attackers to craft payment confirmations with reduced amounts. An attacker can initiate a booking, intercept or forge the payment confirmation, and approve the appointment at a lower cost. No authentication is required and the attack is network-accessible. The vulnerability affects versions 1.5.6 through 1.6.2 and was fixed in version 1.6.3.

Affected products

  • BookingPress Appointment Booking Calendar Plugin and Scheduling Plugin 1.5.6 to 1.6.2

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: patched: Fixed in version 1.6.3

References