Junglewise Threat Intelligence

CVE-2026-84767: BookIt bypass vulnerability in WordPress plugin

CVE-2026-84767 · Severity: medium · CVSS 5.3 · Published 2026-09-03

Vendors: StellarWP.

Executive brief

BookIt is a WordPress plugin used for booking and appointment management on WordPress websites. An unauthenticated attacker can bypass the plugin's security checks, potentially gaining unauthorized access to booking data or functionality without requiring valid credentials.

Technical details

The BookIt WordPress plugin versions 2.6.0.3 and earlier contain an insecure design flaw allowing unauthenticated bypass of security checks. The vulnerability requires no authentication and is network-accessible through the WordPress site. An attacker can circumvent access controls to interact with protected booking functionality. The issue is classified as a bypass/insecure design vulnerability. Patched in version 2.6.0.4 and later.

Affected products

  • StellarWP BookIt <=2.6.0.3

Timeline

  • 2026-09-03: disclosed
  • 2026-09-03: patched: Version 2.6.0.4 patched the vulnerability

References

Related threats