Pinpoint Booking System <= 2.9.9.7.1 - Unauthenticated Price Manipulation via Reservation Price Parameters
- ID
- WPSEC-2026-0553
- Plugin
- Pinpoint Booking System – #1 WordPress Booking Plugin (booking-system)
- Affected
- from 2.9.9.5.0 before 2.9.9.7.2
- Remediation
- Update to 2.9.9.7.2 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-472
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- Pinpoint Booking System on WPSec AttackSurface
- Fix released
- Published
Description
The Pinpoint Booking System plugin for WordPress is vulnerable to price manipulation in versions 2.9.9.5.0 up to, and including, 2.9.9.7.1. This is due to the front-end booking request checking only the reservation's base price against the calendar's prices, while the submitted extras, discount, fees, coupon, total and deposit amounts are stored without server-side verification. Because the PayPal gateway and the WooCommerce integration charge the stored total or deposit amount, this makes it possible for unauthenticated attackers to book reservations and pay an arbitrary, lower price, after which the reservation is confirmed as paid.
References
- https://wpsec.com/vuln/WPSEC-2026-0553/
- https://plugins.svn.wordpress.org/booking-system/tags/2.9.9.7.2/
- https://wordpress.org/plugins/booking-system/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS