[CVE-2026-76586] The Appointment Booking Calendar Plugin and Scheduling Plugi

CVE-2026-76586 | CVSS: 7.5 | 严重级别: HIGH

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price.

参考链接:
https://wpscan.com/vulnerability/bc74bc9b-92ce-434e-a21d-34d7525c8600/

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部