What is CVE-2026-12128?
The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` parameter due to missing authentication on the `dopbsp_woocommerce_add_to_cart` AJAX action registered through `wp_ajax_nopriv_*`. This affects all versions up to and including 2.9.9.6.8. An unauthenticated attacker can modify order prices, so updating to the latest version is strongly recommended.
Azərbaycanca: WordPress üçün Pinpoint Booking System – Version 2 pluginində (`wp_ajax_nopriv_*` vasitəsilə qeydiyyatdan keçmiş `dopbsp_woocommerce_add_to_cart` AJAX əməliyyatında autentifikasiya olmaması səbəbindən `cart_data` parametri ilə qiymət manipulyasiyası zəifliyi aşkarlanıb. Bu, 2.9.9.6.8-ə qədər olan versiyalara təsir edir. İstismar nəticəsində autentifikasiya olunmamış hücumçu sifariş qiymətlərini dəyişdirə bilər, pluginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
In which AJAX action was the price manipulation vulnerability found in the Pinpoint Booking System – Version 2 plugin?
The vulnerability was found in the `dopbsp_woocommerce_add_to_cart` AJAX action registered through `wp_ajax_nopriv_*`.
Is authentication required for an attacker to exploit CVE-2026-12128?
No, an unauthenticated attacker can modify order prices.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.