MEDIUMCVSS 5.3Vulnerability

CVE-2026-8840

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.36. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary reservations as paid or completed, cancel legitimate payments, auto-approve reservations, and trigger transactional booking emails by writing attacker-supplied payment status and transaction data directly into the payments table. The auto-approval of reservations is only triggered when the 'enable_psuccess_approval' site option is enabled, but payment status manipulation and email dispatch are exploitable regardless of that setting.

Properties

severity
MEDIUM
cvss_severity
MEDIUM
cvss_score
5.3
epss_score
0.00547
retrieved_at
2026-10-09T03:34:45+00:00
last_source
FIRST EPSS
score
5.3
cve_id
CVE-2026-8840
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
signal_observed_at
2026-09-11T17:55:57+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
published_at
2026-08-15T03:16:48.357
last_modified
2026-08-20T12:48:10.287
epss_percentile
0.4406

Related Entities (3)

ENRICHED_BY (1)

→[Source]FIRST EPSS

HAS_WEAKNESS (1)

→[Weakness]Missing Authorization

DESCRIBED_BY (1)

→[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph