What is CVE-2026-9830?
The Bookingpress Appointment Booking Pro WordPress plugin before version 5.7.3 fails to properly invoke its REST permission callback, leaving API routes accessible without authentication. This allows unauthenticated attackers to read customer booking data and modify other users' information. Updating the plugin to the latest version is strongly recommended.
Azərbaycanca: Bookingpress Appointment Booking Pro WordPress plaqininin 5.7.3-dən əvvəlki versiyalarında REST icazə yoxlaması səhv konfiqurasiya olunub. Bu zəiflik autentifikasiya olunmamış şəxslərə API vasitəsilə müştəri bron məlumatlarını oxumağa və digər istifadəçi məlumatlarını dəyişməyə imkan verir. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
What type of data is affected by CVE-2026-9830?
This vulnerability allows unauthenticated attackers to read customer booking data and modify other users' information via the API.
What action is recommended to mitigate CVE-2026-9830?
It is strongly recommended to update the plugin to the latest version (5.7.3 or higher) immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.