The Pinpoint Booking System WordPress plugin through 2.9.9.6.9 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation.
History

Tue, 11 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Pinpoint
Pinpoint pinpoint Booking System
Wordpress
Wordpress wordpress
Vendors & Products Pinpoint
Pinpoint pinpoint Booking System
Wordpress
Wordpress wordpress

Mon, 10 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-284

Mon, 10 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Pinpoint Booking System WordPress plugin through 2.9.9.6.9 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation.
Title Pinpoint Booking System <= 2.9.9.6.9 - Unauthenticated Arbitrary Booking Price Manipulation
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-08-10T06:00:17.447Z

Updated: 2026-08-10T06:00:17.447Z

Reserved: 2026-07-09T11:07:35.406Z

Link: CVE-2026-15229

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-10T07:16:47.607

Modified: 2026-08-10T07:16:47.607

Link: CVE-2026-15229

cve-icon Redhat

No data.