Description
The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an unauthenticated attacker obtain confirmed, fully paid appointments and events without any payment being collected.
Published: 2026-09-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated payment bypass allowing fraudulent paid bookings
Action: Immediate Patch
AI Analysis

Impact

The Booking for Appointments and Events Calendar WordPress plugin versions before 9.8.1 accepts booking requests that are unauthenticated and blindly trusts the payment gateway name supplied in the request. The plugin does not verify that a payment has actually been processed, letting an attacker create bookings that appear fully paid without any money being collected. This flaw (CWE‑284) permits the production of illegitimate paid appointments and events that can be invoiced to customers or recorded as revenue.

Affected Systems

WordPress sites running the Booking for Appointments and Events Calendar plugin prior to version 9.8.1, including all supported releases from 9.0 through 9.7.x, are affected. The vulnerability is present wherever the post-payment verification step is missing, regardless of whether a payment gateway has been configured on the site.

Risk and Exploitability

The vulnerability is remotely exploitable without any authentication. A CVSS score of 5.3 indicates moderate severity, while the EPSS score of <1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV, meaning no confirmed active exploitation is reported. Nonetheless, the ability to create unlimited fraudulent paid bookings could lead to significant financial loss and reputational damage for affected organisations. Attacks can be launched simply by sending booking requests that name any payment gateway, including unconfigured ones, exploiting a broken access control.

Generated by OpenCVE AI on September 15, 2026 at 18:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Booking for Appointments and Events Calendar plugin to version 9.8.1 or newer, which verifies that a payment has truly been received before marking a booking as paid.
  • Disable the plugin is not required, preventing any reference to unconfigured gateways in booking requests.
  • Audit recent bookings for entries that appear paid without an associated payment transaction and reverse or correct those records to mitigate potential financial impact.

Generated by OpenCVE AI on September 15, 2026 at 18:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an unauthenticated attacker obtain confirmed, fully paid appointments and events without any payment being collected.
Title Amelia Pro 9.0 - 9.8 - Unauthenticated Payment Bypass
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:35:52.587Z

Reserved: 2026-08-21T07:25:37.099Z

Link: CVE-2026-77689

cve-icon Vulnrichment

Updated: 2026-09-12T15:25:29.927Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T06:16:24.860

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-77689

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:00:15Z

Weaknesses