Executive brief
BookIt is a WordPress plugin used for booking and appointment management on WordPress websites. An unauthenticated attacker can bypass the plugin's security checks, potentially gaining unauthorized access to booking data or functionality without requiring valid credentials.
Technical details
The BookIt WordPress plugin versions 2.6.0.3 and earlier contain an insecure design flaw allowing unauthenticated bypass of security checks. The vulnerability requires no authentication and is network-accessible through the WordPress site. An attacker can circumvent access controls to interact with protected booking functionality. The issue is classified as a bypass/insecure design vulnerability. Patched in version 2.6.0.4 and later.
Affected products
- StellarWP BookIt <=2.6.0.3
Timeline
- 2026-09-03: disclosed
- 2026-09-03: patched: Version 2.6.0.4 patched the vulnerability