Review
BookingPress
CVE published 2026-07-27
CVE-2026-9830
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 has a vulnerability that allows unauthenticated attackers to read customer booking data and modify other users' bookings due to a missing REST permission callback. This oversight in the plugin's API namespaces makes it possible for attackers to exploit this vulnerability without authentication, potentially leading to unauthorized acces [truncated]