{
 "id": "WPSEC-2026-0553",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0553/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0553/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0553/index.md",
 "title": "Pinpoint Booking System <= 2.9.9.7.1 - Unauthenticated Price Manipulation via Reservation Price Parameters",
 "description": "The Pinpoint Booking System plugin for WordPress is vulnerable to price manipulation in versions 2.9.9.5.0 up to, and including, 2.9.9.7.1. This is due to the front-end booking request checking only the reservation's base price against the calendar's prices, while the submitted extras, discount, fees, coupon, total and deposit amounts are stored without server-side verification. Because the PayPal gateway and the WooCommerce integration charge the stored total or deposit amount, this makes it possible for unauthenticated attackers to book reservations and pay an arbitrary, lower price, after which the reservation is confirmed as paid.",
 "plugin": {
  "slug": "booking-system",
  "name": "Pinpoint Booking System",
  "full_name": "Pinpoint Booking System – #1 WordPress Booking Plugin",
  "wordpress_org": "https://wordpress.org/plugins/booking-system/",
  "advisories_url": "https://wpsec.com/vuln/plugin/booking-system/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/booking-system"
 },
 "type": "BYPASS",
 "cwe": [
  "CWE-472"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "2.9.9.5.0",
    "from_inclusive": true,
    "to": "2.9.9.7.2",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 2.9.9.5.0 before 2.9.9.7.2"
  ]
 },
 "introduced_in": "2.9.9.5.0",
 "fixed_in": "2.9.9.7.2",
 "remediation": "Update to 2.9.9.7.2 or later.",
 "fix_released": "2026-10-06T13:47:32+00:00",
 "published": "2026-10-07T14:47:02+00:00",
 "updated": "2026-10-07T13:54:59.438918+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0553/",
  "https://plugins.svn.wordpress.org/booking-system/tags/2.9.9.7.2/",
  "https://wordpress.org/plugins/booking-system/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/booking-system",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}