PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9830 BookingPress CVE debrief

The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 has a vulnerability that allows unauthenticated attackers to read customer booking data and modify other users' bookings due to a missing REST permission callback. This oversight in the plugin's API namespaces makes it possible for attackers to exploit this vulnerability without authentication, potentially leading to unauthorized access and modification of sensitive booking information.

Vendor
BookingPress
Product
bookingpress-appointment-booking-pro
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-27
Original CVE updated
2026-07-27
Advisory published
2026-07-27
Advisory updated
2026-07-27

Who should care

Users of the bookingpress-appointment-booking-pro WordPress plugin, especially those with customer booking data, should be aware of this vulnerability and take steps to protect their sites. This includes administrators of WordPress installations that utilize the bookingpress-appointment-booking-pro plugin, as well as security teams responsible for monitoring and mitigating potential threats.

Technical summary

The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback. This oversight makes every route in one of its API namespaces reachable without authentication. Consequently, unauthenticated attackers can exploit this vulnerability to read customer booking data and modify other users' bookings. The plugin's failure to implement proper authentication mechanisms for its API namespaces enables attackers to bypass security measures and perform unauthorized actions.

Defensive priority

High priority should be given to updating the bookingpress-appointment-booking-pro WordPress plugin to version 5.7.3 or later to prevent exploitation of this vulnerability. Additionally, reviewing and monitoring API namespace routes for unauthorized access attempts and implementing compensating controls can help mitigate potential risks.

Recommended defensive actions

  • Update the bookingpress-appointment-booking-pro WordPress plugin to version 5.7.3 or later.
  • Review and monitor API namespace routes for unauthorized access attempts.
  • Implement additional security measures such as Web Application Firewalls (WAFs) to detect and prevent exploitation attempts.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

Evidence for this vulnerability comes from the CVE record and NVD detail, which provide information on the affected plugin and its version. However, further details about the vulnerability's impact and exploitation are limited. The CVE record was published on 2026-07-27T07:16:30.503Z and has not been modified since then. The NVD detail and source item URL provide additional context but do not offer extensive information on exploitation or affected systems.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T07:16:30.503Z and has not been modified since then.