CVE-2026-76586
moderateUnauthenticated Payment Price Bypass in Appointment Booking Calendar WordPress Plugin
The Appointment Booking Calendar (scheduling) WordPress plugin prior to 1.6.3 fails to verify that the amount actually paid matches the server-side price staged for a booking when it confirms an online payment (CWE-284, improper access control). Because the payment confirmation flow is reachable over the network without authentication or user interaction, an unauthenticated attacker can manipulate the amount paid during online payment confirmation so the plugin approves the appointment as fully paid while only a fraction of the price is collected. The attacker gains confirmed, paid-status appointments at a reduced cost, causing direct revenue loss and allowing cheap or underpaid bookings to occupy paid calendar slots. Any WordPress site running the plugin before 1.6.3 that uses its online payment feature is affected. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS assigns a roughly 0.2% probability of exploitation within 30 days, so no in-the-wild exploitation is currently known.
What to do: Update to Appointment Booking Calendar 1.6.3 or later. Until patched, sites using the online payment feature should reconcile approved bookings against payment-gateway records and review recent appointments for approvals made below the listed price. As a stopgap, disabling or restricting the online payment confirmation flow reduces exposure.
| CodePeople Appointment Booking Calendar Plugin and Scheduling Plugin (WordPress plugin) | before 1.6.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price.
- Ecosystems
- WordPress
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.