[CVE-2026-77689] The Booking for Appointments and Events Calendar WordPress

CVE-2026-77689 | CVSS: 5.3 | 严重级别: MEDIUM

The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an unauthenticated attacker obtain confirmed, fully paid appointments and events without any payment being collected.

参考链接:
https://wpscan.com/vulnerability/ac597716-193d-419f-b55c-802ee979385e/

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部