SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-76586

HIGH · CVSS 7.5 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-29 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Appointment Booking Calendar and Scheduling plugins for WordPress prior to version 1.6.3 are vulnerable due to a lack of verification between the payment amount and the server-side price for bookings. This flaw allows unauthenticated users to exploit the system, potentially approving appointments for significantly reduced prices. WordPress site administrators using these plugins should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-76586
Severity
HIGH
CVSS
7.5
EPSS
0.21%
WordPress

Original NVD Description

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price.