Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 13 May 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Zealopensource Zealopensource smart Appointment & Booking |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Zealopensource Zealopensource smart Appointment & Booking |
Tue, 12 May 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 May 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Smart Appointment & Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and a nonce validation logic flaw in the saab_cancel_booking() function in all versions up to, and including, 1.0.8. The nonce check uses && (AND) instead of || (OR), which means providing any value for the security parameter causes the entire check to be skipped. This makes it possible for unauthenticated attackers to cancel arbitrary bookings by supplying a predictable booking ID. | |
| Title | Smart Appointment & Booking <= 1.0.8 - Missing Authorization to Unauthenticated Arbitrary Booking Cancellation | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-12T12:47:37.797Z
Reserved: 2026-04-06T11:20:41.603Z
Link: CVE-2026-5693
Updated: 2026-05-12T12:47:34.077Z
Status : Deferred
Published: 2026-05-12T09:16:54.953
Modified: 2026-05-12T14:03:52.757
Link: CVE-2026-5693
No data.
OpenCVE Enrichment
Updated: 2026-05-13T10:39:31Z