WordPress Plugin Vulnerabilities

Appointment Booking Lite < 2.4.8 - Unauthenticated Arbitrary Reservation Deletion

Description

The plugin does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated endpoint, allowing unauthenticated attackers to permanently delete other users' reservations. This is an incomplete fix of CVE-2026-9180: the deletion remains reachable on sites using payment confirmation, confirmed through version 2.4.7.

Proof of Concept

Affects Plugins

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Ahmed Hashim Ismael
Submitter
Ahmed Hashim Ismael
Verified
Yes

Timeline

Publicly Published
2026-08-31 (about 2 days ago)
Added
2026-08-31 (about 1 day ago)
Last Updated
2026-08-31 (about 1 day ago)

Other