Ghostwire

CVE-2026-15250: The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated...

HIGH CVSS 0.0

Published: July 30, 2026 | Last Modified: July 30, 2026

Description

The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its public booking funnel, allowing an unauthenticated user to assign a privileged booking field such as the approval status and thereby bypass the site's booking approval workflow.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References