Authorization Bypass in Booking Calendar Plugin for WordPress
CVE-2026-8840
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 August 2026
What is CVE-2026-8840?
The Booking Calendar, Appointment Booking System plugin for WordPress is susceptible to an authorization bypass, enabling unauthorized users to execute actions without proper validation. This exploitation allows unauthenticated attackers to manipulate payment status, mark reservations as paid or completed, cancel legitimate payments, and send booking emails by directly writing to the payments table. Notably, while auto-approval of reservations can occur if the 'enable_psuccess_approval' site option is turned on, the vulnerability allows for various forms of manipulation irrespective of this setting.
Affected Version(s)
Booking calendar, Appointment Booking System 0 <= 3.2.36