WordPress Plugin Vulnerabilities

BookingPress 1.5.6 - 1.6.2 - Unauthenticated Booking Price Manipulation via PayPal Payment Confirmation

Description

The plugin does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price.

Proof of Concept

Affects Plugins

References

Classification

Type
ACCESS CONTROLS
CWE
CVSS

Miscellaneous

Original Researcher
Nguyen Phuoc Thinh - HPT Vietnam Corporation
Submitter
Nguyen Phuoc Thinh - HPT Vietnam Corporation
Verified
Yes

Timeline

Publicly Published
2026-08-27 (about 2 days ago)
Added
2026-08-27 (about 1 day ago)
Last Updated
2026-08-27 (about 1 day ago)

Other