What is CVE-2026-14831?
The Easy Booking WordPress plugin before version 3.5.0 fails to enforce the configured minimum booking duration on the server side when adding to cart and calculating price. This allows unauthenticated users to place bookings below the minimum duration and complete underpriced orders. Updating the plugin to version 3.5.0 or later is recommended.
Azərbaycanca: Easy Booking WordPress plaqinində (3.5.0-dən əvvəlki versiyalar) server tərəfində minimum rezervasiya müddətini məcburi tətbiq etməmə zəifliyi mövcuddur. Bu, autentifikasiya olunmamış istifadəçilərə minimum müddətdən aşağı sifarişlər yerləşdirməyə imkan verir. Plaqini 3.5.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which versions of the Easy Booking plugin are affected by CVE-2026-14831?
This vulnerability affects all versions of the Easy Booking plugin prior to 3.5.0.
What can an unauthenticated user do by exploiting this vulnerability?
Unauthenticated users can place bookings below the configured minimum duration and complete underpriced orders due to the lack of server-side enforcement.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.