SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-15250

MEDIUM · CVSS 5.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The Appointment Booking Plugin for WordPress versions prior to 5.6.8 is vulnerable, allowing unauthenticated users to manipulate booking fields, including the approval status, through the public booking funnel. This flaw can lead to unauthorized bypassing of the site's booking approval workflow, potentially compromising the integrity of booking processes. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-15250
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%
WordPress

Original NVD Description

The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its public booking funnel, allowing an unauthenticated user to assign a privileged booking field such as the approval status and thereby bypass the site's booking approval workflow.