Description
Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.
Published: 2026-09-03
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in WordPress BookIt versions up to 2.6.0.3 allows an attacker to bypass authentication controls without needing valid credentials, which means any person with network access to the WordPress site could potentially exploit the flaw to view or modify booking data or trigger plugin functions meant for authenticated users. The weakness is a form of improper authentication (CWE-345), which can lead to unauthorized data exposure or unauthorized modification of bookings, affecting the confidentiality and integrity of the booking system. No confirmation of remote code execution is given; the impact is confined to accessing or manipulating booking operations that should be restricted to logged‑in users.

Affected Systems

Vendors and products affected are the WordPress BookIt plugin from Nexcess (BookIt). Only the 2.6.0.3 release and earlier versions are impacted. Versions newer than 2.6.0.4 are not affected.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity. EPSS information is not available, so the likelihood of exploitation cannot be quantified at this time. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation. The likely attack vector is any unauthenticated HTTP request to the WordPress site that interacts with the BookIt plugin. Without additional elevation steps, an attacker can use the plugin’s exposed endpoints to access or manipulate booking information. The scope of impact is limited to the affected WordPress site’s booking system.

Generated by OpenCVE AI on September 3, 2026 at 17:23 UTC.

Remediation

Vendor Solution

Update the WordPress BookIt Plugin to the latest available version (at least 2.6.0.4).


OpenCVE Recommended Actions

  • Update the WordPress BookIt Plugin to at least version 2.6.0.4.
  • Disable or remove the BookIt plugin if the booking functionality is no longer required.
  • Implement or review access controls and network filtering to limit exposure of the plugin’s endpoints to trusted users or IP ranges.

Generated by OpenCVE AI on September 3, 2026 at 17:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.
Title WordPress BookIt plugin <= 2.6.0.3 - Bypass Vulnerability vulnerability
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-03T16:31:50.759Z

Reserved: 2026-09-02T09:57:42.761Z

Link: CVE-2026-84767

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-03T17:17:27.880

Modified: 2026-09-03T17:25:25.113

Link: CVE-2026-84767

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T17:30:07Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity