AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-14831

MEDIUM · CVSS 5.3 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Easy Booking WordPress plugin prior to version 3.5.0 is vulnerable as it fails to enforce the configured minimum booking duration on the server side, allowing unauthenticated users to bypass restrictions and place bookings below the minimum duration. This flaw can lead to financial losses due to underpriced orders being processed. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-14831
Severity
MEDIUM
CVSS
5.3
EPSS
0.31%
WordPress

Original NVD Description

The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking duration on the server side when adding to cart and calculating the booking price, allowing unauthenticated users to place below-minimum bookings and complete underpriced orders.