CVE-2026-9830

BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug

The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.


We have discovered 755 live websites that are affected by CVE-2026-9830.

Run a Free Instant Scan




Affected Software

Product  Bookingpress Appointment Booking
Category Wordpress Plugins
Vulnerable Domains755 live websites (100% of Bookingpress Appointment Booking install base)
Vulnerable Versions
  • from 0 through 5.7.3
Vulnerable Versions Count58 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-287 Improper Authentication



Details

  • Published - Jul 27, 2026
  • Updated - Jul 27, 2026

Credits

  • Kolja Zuelsdorf (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-9830
United States170 websites



Germany160 websites
GB75 websites
France39 websites
India35 websites
Netherlands32 websites
Australia22 websites
Italy20 websites
Switzerland19 websites
Cyprus19 websites

Website Distribution by TLD

Number of websites using CVE-2026-9830
.com333 websites
.de72 websites
.co.uk49 websites
.nl32 websites
.fr25 websites
.com.au21 websites
.it18 websites
.ch16 websites
.org13 websites
.ca11 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-9830

Top websites that are affected by CVE-2026-9830. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****************.de Germany*,***,***
*****.**.za South Africa*,***,***
**************.com United States*,***,***
*************.fr France*,***,***
********.com France*,***,***
*******.it Italy*,***,***
******.nl Netherlands*,***,***
*****************.de Germany*,***,***
******************.de Germany*,***,***
*********.com Bulgaria*,***,***
See full domain list

FAQ

CVE-2026-9830 is Improper Authentication in Bookingpress Appointment Booking
A total of 755 websites have been identified as vulnerable to CVE-2026-9830, based on global website indexing conducted by WebTechSurvey.
The Bookingpress Appointment Booking is affected by the CVE-2026-9830 vulnerability.
Bookingpress Appointment Booking versions up to 5.7.3 are vulnerable to CVE-2026-9830.
CVE-2026-9830 is resolved in version 5.7.3 of Bookingpress Appointment Booking.