Executive brief
BookingPress Pro, a popular WordPress plugin for managing appointments and schedules, contains a security flaw that allows unauthorized access to its internal database. An attacker can exploit this to view sensitive customer information, including names, email addresses, and phone numbers. Additionally, attackers can reschedule or modify existing appointments without the customer's or administrator's knowledge, potentially disrupting business operations and damaging customer trust.
Technical details
The BookingPress Pro plugin before version 5.7.3 fails to correctly implement or invoke its REST permission callback for specific API namespaces. This oversight leaves several routes, such as /calendar, /appointment/reschedule, and /time, accessible to unauthenticated users. An attacker can send unauthenticated POST requests to these endpoints to perform mass disclosure of customer PII (names, emails, phone numbers) or tamper with existing bookings by rescheduling them. The vulnerability is classified as an authentication bypass (CWE-287) due to the missing authorization checks on the REST API handlers.
Affected products
- BookingPress BookingPress Pro before 5.7.3
Timeline
- 2026-07-06: disclosed: Publicly published by researcher
- 2026-07-27: advisory: NVD publication date