Impact
The Pinpoint Booking System – Version 2 plugin for WordPress contains an improper input validation flaw (CWE-20). An unauthenticated attacker can send the cart_data parameter to the dopbsp_woocommerce_add_to_cart AJAX action without authentication, nonce, or server‑side recalculation of pricing. The attacker’s supplied price_total is written directly to the database and later applied to the product price during checkout, enabling the purchase of any bookable product at a price chosen by the attacker.
Affected Systems
The vulnerability impacts installations of the Pinpoint Booking System plugin version 2 up to and including 2.9.9.6.8 on WordPress sites that use WooCommerce for booking products. Any WordPress deployment running one of these affected plugin versions is susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score is not available, suggesting the probability of exploitation is uncertain but not negligible. The flaw allows unauthenticated exploitation via the web interface, and because it directly changes checkout prices, it represents a clear financial risk. The vulnerability is not listed in the CISA KEV catalog, but the lack of authentication and non‑validation make it a high‑priority issue for sites that rely on accurate booking pricing.
OpenCVE Enrichment