Junglewise Threat Intelligence

CVE-2026-9830: BookingPress Pro authentication bypass in REST API callback

CVE-2026-9830 · Severity: info · CVSS 8.2 · Published 2026-07-27

Executive brief

BookingPress Pro, a popular WordPress plugin for managing appointments and schedules, contains a security flaw that allows unauthorized access to its internal database. An attacker can exploit this to view sensitive customer information, including names, email addresses, and phone numbers. Additionally, attackers can reschedule or modify existing appointments without the customer's or administrator's knowledge, potentially disrupting business operations and damaging customer trust.

Technical details

The BookingPress Pro plugin before version 5.7.3 fails to correctly implement or invoke its REST permission callback for specific API namespaces. This oversight leaves several routes, such as /calendar, /appointment/reschedule, and /time, accessible to unauthenticated users. An attacker can send unauthenticated POST requests to these endpoints to perform mass disclosure of customer PII (names, emails, phone numbers) or tamper with existing bookings by rescheduling them. The vulnerability is classified as an authentication bypass (CWE-287) due to the missing authorization checks on the REST API handlers.

Affected products

  • BookingPress BookingPress Pro before 5.7.3

Timeline

  • 2026-07-06: disclosed: Publicly published by researcher
  • 2026-07-27: advisory: NVD publication date

References

Related threats