THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-77689 (MEDIUM 5.3) — The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never confi

[NVD] CVE-2026-77689 (MEDIUM 5.3) — The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never confi

mednvdPublished 2026-09-12

CVE-2026-77689 CVSS: 5.3 MEDIUM Published: 2026-09-12T06:16:24.860

The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an unauthenticated att

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-77689