AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-15229

MEDIUM · CVSS 5.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Pinpoint Booking System plugin for WordPress, up to version 2.9.9.6.9, is vulnerable due to a lack of server-side validation for booking prices, enabling unauthenticated users to create bookings at any price, including zero. This flaw can lead to unauthorized reservations and potential financial losses for businesses relying on this plugin. WordPress site administrators using this plugin should prioritize immediate updates to mitigate this risk.

CVE
CVE-2026-15229
Severity
MEDIUM
CVSS
5.3
EPSS
0.18%
WordPress

Original NVD Description

The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation.