What is CVE-2026-15229?
CVE-2026-15229 is a vulnerability in the Pinpoint Booking System WordPress plugin where missing server-side validation of booking prices allows unauthenticated users to create bookings at an arbitrary price, including zero, and get instant approval. This can lead to unauthorized free reservations. Updating to the latest plugin version is recommended.
Azərbaycanca: CVE-2026-15229, Pinpoint Booking System WordPress plaginində server tərəfində qiymət doğrulamasının olmaması səbəbindən autentifikasiya olunmamış istifadəçilərə sifariş qiymətini sıfırlamağa imkan verir. Təcavüzkar bu boşluqdan istifadə edərək ödənişsiz rezervasiya əldə edə bilər. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What does CVE-2026-15229 allow in the Pinpoint Booking System plugin?
It allows unauthenticated users to create bookings at an arbitrary price, including zero, and get instant approval, leading to unauthorized free reservations.
What solution is recommended for CVE-2026-15229?
Updating to the latest plugin version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.