PatchSiren

BookingPress CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review BookingPress CVE published 2026-07-27

CVE-2026-9830

The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 has a vulnerability that allows unauthenticated attackers to read customer booking data and modify other users' bookings due to a missing REST permission callback. This oversight in the plugin's API namespaces makes it possible for attackers to exploit this vulnerability without authentication, potentially leading to unauthorized acces [truncated]