# Pinpoint Booking System <= 2.9.9.7.1 - Unauthenticated Price Manipulation via Reservation Price Parameters

- **ID:** WPSEC-2026-0553
- **Plugin:** Pinpoint Booking System – #1 WordPress Booking Plugin (`booking-system`), https://wordpress.org/plugins/booking-system/
- **Affected versions:** from 2.9.9.5.0 before 2.9.9.7.2
- **Fixed in:** 2.9.9.7.2 (Update to 2.9.9.7.2 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-472
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/booking-system
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0553/

## Description

The Pinpoint Booking System plugin for WordPress is vulnerable to price manipulation in versions 2.9.9.5.0 up to, and including, 2.9.9.7.1. This is due to the front-end booking request checking only the reservation's base price against the calendar's prices, while the submitted extras, discount, fees, coupon, total and deposit amounts are stored without server-side verification. Because the PayPal gateway and the WooCommerce integration charge the stored total or deposit amount, this makes it possible for unauthenticated attackers to book reservations and pay an arbitrary, lower price, after which the reservation is confirmed as paid.

## References

- https://wpsec.com/vuln/WPSEC-2026-0553/
- https://plugins.svn.wordpress.org/booking-system/tags/2.9.9.7.2/
- https://wordpress.org/plugins/booking-system/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0553/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
