CVE-2026-9830
HIGHBookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-9830. PoCs published by ChPratik.
AI-analyzed exploit summary This repository contains two comprehensive technical reports analyzing CVE-2026-9830, an authentication bypass vulnerability in BookingPress Appointment Booking Pro WordPress plugin (<5.7.3). The reports include root cause analysis (REST API permission_callback misconfiguration), patch diff analysis, source-code review, CPE validation, exploit maturity assessment, and threat intelligence.
Description
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.
Exploits (1)
This repository contains two comprehensive technical reports analyzing CVE-2026-9830, an authentication bypass vulnerability in BookingPress Appointment Booking Pro WordPress plugin (<5.7.3). The reports include root cause analysis (REST API permission_callback misconfiguration), patch diff analysis, source-code review, CPE validation, exploit maturity assessment, and threat intelligence.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N