SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-11866

MEDIUM · CVSS 5.4 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Appointment Booking Plugin for WordPress prior to version 5.6.3 is vulnerable to Cross-Site Request Forgery (CSRF) due to inadequate nonce validation on critical state-changing actions. This flaw could allow attackers to execute privileged operations, such as altering booking configurations or severing payment gateway connections, by exploiting a logged-in administrator's session. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential risks.

CVE
CVE-2026-11866
Severity
MEDIUM
CVSS
5.4
EPSS
0.10%
WordPress

Original NVD Description

The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central request dispatcher, allowing attackers to perform privileged actions, such as overwriting the booking-form configuration or disconnecting the connected payment gateway, via Cross-Site Request Forgery against a logged-in administrator.