CVE-2026-6960

CRITICAL

BookingPress Pro <= 5.6 - Unauthenticated Arbitrary File Upload via Signature Custom Field

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-6960. PoCs published by xxconi.

AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2026-6960, an unauthenticated arbitrary file upload vulnerability in BookingPress Pro ≤ 5.6. The exploit uploads a PHP shell via a signature custom field and verifies execution by running a command.

Description

The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in all versions up to, and including, 5.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The vulnerability can only be exploited if a signature custom field is added to the booking form.

Exploits (1)

github WORKING POC
by xxconi · pythonpoc
https://github.com/xxconi/CVE-2026-6960

This repository contains a functional Python exploit for CVE-2026-6960, an unauthenticated arbitrary file upload vulnerability in BookingPress Pro ≤ 5.6. The exploit uploads a PHP shell via a signature custom field and verifies execution by running a command.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: BookingPress Pro (WordPress plugin) ≤ 5.6
No auth needed
Prerequisites: WordPress site with BookingPress Pro ≤ 5.6 installed · Network access to the target
mistral-large-3 · analyzed May 23, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0067
EPSS Percentile 48.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
Repute Infosystems/BookingPress Appointment Booking Pro < 5.6
Published May 21, 2026
Tracked Since May 22, 2026