CVE-2026-57367

WordPress WP Booking System plugin < 5.12.8.1 - Broken Access Control vulnerability

Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.


We have discovered 1,626 live websites that are affected by CVE-2026-57367.

Run a Free Instant Scan




Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jul 23, 2026
  • Updated - Jul 23, 2026

Credits

  • Austin Ginder | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-57367
United States206 websites



Germany396 websites
GB153 websites
France137 websites
Netherlands110 websites
Belgium75 websites
Italy51 websites
Denmark49 websites
Switzerland45 websites
Spain42 websites

Website Distribution by TLD

Number of websites using CVE-2026-57367
.com478 websites
.de319 websites
.co.uk130 websites
.nl91 websites
.fr57 websites
.be55 websites
.ch41 websites
.it31 websites
.dk29 websites
.eu26 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-57367

Top websites that are affected by CVE-2026-57367. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.********.gov United States**,***
******************.be Belgium**,***
****************.it Italy***,***
******.com United States***,***
************.**.uk Germany***,***
*************.ch Switzerland***,***
********.com France***,***
***************.**.uk GB***,***
**********.fr France***,***
*****************.com Canada***,***
See full domain list