The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` parameter in all versions up to, and including, 2.9.9.6.8. This is due to the `dopbsp_woocommerce_add_to_cart` AJAX action being registered via `wp_ajax_nopriv_*` with no authentication, no nonce verification, and no server-side recalculation of pricing — the `update` handler reads `price_total` directly from the attacker-controlled `cart_data` POST parameter and persists it to the database via `$wpdb->insert()` without validating it against the calendar's configured pricing. The `woocommerce_before_calculate_totals` callback subsequently reads the stored attacker-supplied value back from the database and passes it directly to `$product->set_price()` without recomputing from calendar settings. This makes it possible for unauthenticated attackers to override the WooCommerce checkout price of any bookable product tied to a booking calendar to an arbitrary value, effectively enabling the purchase of any such product at a self-chosen price.
We have discovered 260 live websites that are affected by CVE-2026-12128.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 260 live websites (59% of Booking System install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 11 versions ( 73% of all versions) |
| 28 websites | |
| 42 websites | |
| 27 websites | |
| 25 websites | |
| 20 websites | |
| 16 websites | |
| 12 websites | |
| 10 websites | |
| 7 websites | |
| 6 websites |
| .com | 95 websites |
| .de | 22 websites |
| .nl | 14 websites |
| .co.uk | 12 websites |
| .fr | 11 websites |
| .ch | 10 websites |
| .es | 10 websites |
| .at | 6 websites |
| .eu | 5 websites |
| .it | 5 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.de | *,***,*** | ||
| ****************************.***.au | *,***,*** | ||
| ******************.com | *,***,*** | ||
| *************.es | *,***,*** | ||
| *************.at | *,***,*** | ||
| ********.de | *,***,*** | ||
| *************************.com | *,***,*** | ||
| **********************.***.uk | *,***,*** | ||
| ********.ch | *,***,*** | ||
| *******.org | *,***,*** |
FAQ