What is CVE-2026-8840?
This CVE describes an authorization bypass vulnerability in the Booking calendar, Appointment Booking System plugin for WordPress, affecting versions up to and including 3.2.36. Due to improper verification of user permissions, an unauthenticated attacker can potentially exploit this flaw to gain unauthorized access to certain actions. Site administrators using this plugin should immediately update to the latest patched version.
Azərbaycanca: Bu CVE Booking calendar, Appointment Booking System adlı WordPress plagininin 3.2.36 və əvvəlki versiyalarını təsir edən authorization bypass zəifliyidir. Plagin istifadəçinin əməliyyat icra etmək səlahiyyətini düzgün yoxlamadığı üçün, autentifikasiya olunmamış hücumçular müəyyən funksiyalara icazəsiz giriş əldə edə bilər. Plagindən istifadə edən sayt adminləri dərhal son versiyaya yeniləmə etməlidirlər.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which WordPress plugin is affected by the CVE-2026-8840 vulnerability?
This vulnerability affects the Booking calendar, Appointment Booking System plugin for WordPress, in versions up to and including 3.2.36.
Is authentication required for an attacker to exploit the authorization bypass vulnerability in CVE-2026-8840?
No, due to improper verification of user permissions in the plugin, an unauthenticated attacker can potentially exploit this flaw to gain unauthorized access to certain actions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.