CVE-2026-62135
CVE-2026-62135 is a MEDIUM severity vulnerability in Booktics plugin versions <= 1.0.24. It allows unauthenticated broken access control. Defenders should assess exposure, prioritize remediation, and verify inventory.
These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-62135 is a MEDIUM severity vulnerability in Booktics plugin versions <= 1.0.24. It allows unauthenticated broken access control. Defenders should assess exposure, prioritize remediation, and verify inventory.
The Booktics – Booking Calendar for Appointments and Service Businesses plugin for WordPress is vulnerable to unauthorized modification of data. A vulnerability exists in all versions up to, and including, 1.0.23 due to the create_order_permission() permission callback on the POST /wp-json/booktics/v1/orders REST route unconditionally returning true. This, combined with find_and_update_guest() overwriting [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:20.340Z and has not been modified since then. This unauthenticated broken authentication vulnerability in WP Event Solution plugin versions <= 4.1.9 has a CVSS score of 6.5 and is classified as MEDIUM severity. Users of WP Event Solution plugin versions <= 4.1.9 should verify and apply patc [truncated]
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a regression in versions from 4.0.26 up to and including 4.1.15. This regression affects the payment_complete() function in PaymentController.php, allowing unauthenticated attackers to manipulate ticket orders. The vulnerability has a CVSS score of 5.3 and is c [truncated]
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter in all versions up to, and including, 4.1.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scr [truncated]
The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to list, create, update, delete, clone, [truncated]
CVE-2025-68045 is a HIGH severity vulnerability in the WP Event Solution plugin for WordPress. The vulnerability has a CVSS score of 7.5 and is categorized as Unauthenticated Broken Access Control. It affects plugin versions <= 4.1.12.
CVE-2026-40776 is a HIGH severity vulnerability in WP Event SOlution plugin versions <= 4.1.8. The vulnerability has a CVSS score of 7.5 and is categorized as Unauthenticated Broken Access Control. It was published on [cvePublishedAt] and last modified on [cveModifiedAt].