CVE 9.8 CRITICAL

BookingPress Pro <= 5.6 - Unauthenticated Arbitrary File Upload via Signature Custom Field_CVE-2026-6960

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in all versions up to, and including, 5.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The vulnerability can only be exploited if a signature custom field is added to the booking form.

AI Analysis

Unauthenticated arbitrary file upload vulnerability due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function

Basic Information

ID CVE-2026-6960
Source Wordfence
Published May 21, 2026 at 21:27

Affected Product

Vendor Repute Infosystems
Product BookingPress Appointment Booking Pro
Affected Versions Repute Infosystems BookingPress Appointment Booking Pro 0

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor Repute Infosystems
Product BookingPress Pro
Version <= 5.6

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.