CVE-2026-9830

HIGH

BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-9830. PoCs published by ChPratik.

AI-analyzed exploit summary This repository contains two comprehensive technical reports analyzing CVE-2026-9830, an authentication bypass vulnerability in BookingPress Appointment Booking Pro WordPress plugin (<5.7.3). The reports include root cause analysis (REST API permission_callback misconfiguration), patch diff analysis, source-code review, CPE validation, exploit maturity assessment, and threat intelligence.

Description

The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.

Exploits (1)

github WRITEUP
by ChPratik · poc
https://github.com/ChPratik/CVE-2026-9830

This repository contains two comprehensive technical reports analyzing CVE-2026-9830, an authentication bypass vulnerability in BookingPress Appointment Booking Pro WordPress plugin (<5.7.3). The reports include root cause analysis (REST API permission_callback misconfiguration), patch diff analysis, source-code review, CPE validation, exploit maturity assessment, and threat intelligence.

Classification
Writeup 99%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: BookingPress Appointment Booking Pro WordPress plugin <5.7.3
No auth needed
Prerequisites: BookingPress Pro plugin with REST API addon installed · Network access to WordPress REST API endpoint
mistral-large-3 · analyzed Jul 27, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/5fded411-52fd-4dc5-9a23-b77fcd9cfed2/

Scores

CVSS v3 8.2
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (1)
None/bookingpress-appointment-booking-pro < 5.7.3
Published Jul 27, 2026
Tracked Since Jul 27, 2026