Pinpoint Booking System <= 2.9.9.7.1 - Unauthenticated Price Manipulation via Reservation Price Parameters

Medium 5.3 CWE-472Fixed in 2.9.9.7.2
ID
WPSEC-2026-0553
Plugin
Pinpoint Booking System – #1 WordPress Booking Plugin (booking-system)
Affected
from 2.9.9.5.0 before 2.9.9.7.2
Remediation
Update to 2.9.9.7.2 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-472
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Pinpoint Booking System on WPSec AttackSurface
Fix released
Published

Description

The Pinpoint Booking System plugin for WordPress is vulnerable to price manipulation in versions 2.9.9.5.0 up to, and including, 2.9.9.7.1. This is due to the front-end booking request checking only the reservation's base price against the calendar's prices, while the submitted extras, discount, fees, coupon, total and deposit amounts are stored without server-side verification. Because the PayPal gateway and the WooCommerce integration charge the stored total or deposit amount, this makes it possible for unauthenticated attackers to book reservations and pay an arbitrary, lower price, after which the reservation is confirmed as paid.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0