WordPress Plugin Vulnerabilities

Easy Booking < 3.5.0 - Unauthenticated Minimum Booking Duration Bypass

Description

The plugin does not re-enforce a bookable product's configured minimum booking duration on the server side when adding to cart and calculating the booking price, allowing unauthenticated users to place below-minimum bookings and complete underpriced orders.

Proof of Concept

Affects Plugins

References

Miscellaneous

Original Researcher
marim00
Submitter
marim00
Verified
Yes

Timeline

Publicly Published
2026-07-13 (about 1 month ago)
Added
2026-07-13 (about 1 month ago)
Last Updated
2026-07-13 (about 1 month ago)

Other