Description
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price.
Published: 2026-08-29
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Payment amount manipulation leading to financial loss
Action: Immediate Patch
AI Analysis

Impact

The Appointment Booking Calendar Plugin and Scheduling Plugin before version 1.6.3 do not verify that the amount actually paid matches the server‑side price set for a booking when confirming an online PayPal payment. An unauthenticated attacker can therefore trigger the booking confirmation with a partial or incorrect payment amount, causing the system to record the appointment as fully paid for a fraction of its true cost.

Affected Systems

WordPress installations deploying the Appointment Booking Calendar Plugin or Scheduling Plugin with a version older than 1.6.3 are affected. The plugin is commonly used for booking scheduling and appointments, and the issue remains present in releases from 1.5.6 through 1.6.2.

Risk and Exploitability

Because the flaw is exploitable without authentication and the plugin is publicly available, the risk is high. The EPSS score of less than 1% indicates that active exploitation remains unlikely, but the absence of server‑side payment validation increases the overall risk. The CVSS score of 7.5 represents high severity, and the vulnerability is not yet listed in CISA’s KEV catalog. It is inferred that an attacker can still use the public booking endpoint to manipulate payment totals, as no protection is enforced prior to confirming the booking status.

Generated by OpenCVE AI on August 30, 2026 at 04:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Appointment Booking Calendar Plugin or Scheduling Plugin to version 1.6.3 or later, which implements server‑side validation of the paid amount.
  • If an upgrade is not immediately possible, disable the PayPal payment confirmation endpoint or block unauthenticated traffic to the booking confirmation route until payment verification can be enforced.
  • Implement a server‑side check that compares the recorded booking price with the actual payment amount received before marking the appointment status as paid.

Generated by OpenCVE AI on August 30, 2026 at 04:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 30 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-285

Sun, 30 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 29 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-285

Sat, 29 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price.
Title BookingPress 1.5.6 - 1.6.2 - Unauthenticated Booking Price Manipulation via PayPal Payment Confirmation
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-30T00:56:51.964Z

Reserved: 2026-08-19T14:17:03.913Z

Link: CVE-2026-76586

cve-icon Vulnrichment

Updated: 2026-08-30T00:49:02.874Z

cve-icon NVD

Status : Deferred

Published: 2026-08-29T06:17:34.353

Modified: 2026-08-31T20:14:36.250

Link: CVE-2026-76586

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-30T05:00:05Z

Weaknesses