ZeroHour

CVE-2026-76586

moderate

Unauthenticated Payment Price Bypass in Appointment Booking Calendar WordPress Plugin

CVSS 3.1
7.5 high
EPSS
<1%p11
Published
()
Modified
AI analysis

The Appointment Booking Calendar (scheduling) WordPress plugin prior to 1.6.3 fails to verify that the amount actually paid matches the server-side price staged for a booking when it confirms an online payment (CWE-284, improper access control). Because the payment confirmation flow is reachable over the network without authentication or user interaction, an unauthenticated attacker can manipulate the amount paid during online payment confirmation so the plugin approves the appointment as fully paid while only a fraction of the price is collected. The attacker gains confirmed, paid-status appointments at a reduced cost, causing direct revenue loss and allowing cheap or underpaid bookings to occupy paid calendar slots. Any WordPress site running the plugin before 1.6.3 that uses its online payment feature is affected. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS assigns a roughly 0.2% probability of exploitation within 30 days, so no in-the-wild exploitation is currently known.

What to do: Update to Appointment Booking Calendar 1.6.3 or later. Until patched, sites using the online payment feature should reconcile approved bookings against payment-gateway records and review recent appointments for approvals made below the listed price. As a stopgap, disabling or restricting the online payment confirmation flow reduces exposure.

Affected
CodePeople Appointment Booking Calendar Plugin and Scheduling Plugin (WordPress plugin)before 1.6.3
Estimated exposure
moderatetens of thousands of WordPress sites (≈20k–30k active installs per wordpress.org), with only the subset that enables online payments actually exposed — Estimate based on the plugin's published wordpress.org active-install count, which is in the tens of thousands, reduced by the fact that only sites using the plugin's online payment confirmation feature are vulnerable; no exact exposure…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price.

Ecosystems
WordPress
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.