CVE-2026-16986 - Booking Package < 1.7.25 - Unauthenticated Price Manipulation via Service and Option Cost Parameters
CVE ID :CVE-2026-16986
Published : Aug. 26, 2026, 6 a.m. | 29 minutes ago
Description :The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored service price, deriving the expected charge from attacker-supplied request values instead, so an unauthenticated attacker can pay an arbitrary fraction of a service's real price.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 26, 2026, 6 a.m. | 29 minutes ago
Description :The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored service price, deriving the expected charge from attacker-supplied request values instead, so an unauthenticated attacker can pay an arbitrary fraction of a service's real price.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...