WordPress Plugin Vulnerabilities
BookingPress 1.5.6 - 1.6.2 - Unauthenticated Booking Price Manipulation via PayPal Payment Confirmation
Description
The plugin does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
ACCESS CONTROLS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Nguyen Phuoc Thinh - HPT Vietnam Corporation
Submitter
Nguyen Phuoc Thinh - HPT Vietnam Corporation
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-27 (about 2 days ago)
Added
2026-08-27 (about 1 day ago)
Last Updated
2026-08-27 (about 1 day ago)