Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-76586

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Aug 29, 2026
Vendor unknown

Description

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price.

References