PatchSiren

Easy Booking CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Easy Booking CVE published 2026-08-06

CVE-2026-14831

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:47.090Z and has not been modified since then. The Easy Booking WordPress plugin before 3.5.0 does not enforce a bookable product's configured minimum booking duration on the server side when adding to cart and calculating the booking price, allowing unauthenticated users to place below-mini [truncated]