CVE-2026-14831: Easy Booking < 3.5.0 - Unauthenticated Minimum Booking Duration Bypass
The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking duration on the server side when adding to cart and calculating the booking price, allowing unauthenticated users to place below-minimum bookings and complete underpriced orders.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Easy Booking (WordPress plugin)to a version that resolves this vulnerability.Fixed in 3.5.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14831?
The severity of CVE-2026-14831 is classified as medium with a score of 5.3.
How do I fix CVE-2026-14831?
To fix CVE-2026-14831, update the Easy Booking WordPress plugin to version 3.5.0 or later.
What does CVE-2026-14831 exploit?
CVE-2026-14831 exploits a server-side validation weakness that allows unauthenticated users to bypass minimum booking duration restrictions.
What impact does CVE-2026-14831 have on my website?
CVE-2026-14831 allows unauthenticated users to place bookings that do not meet the minimum duration, potentially resulting in financial loss for the site owner.
When was CVE-2026-14831 published?
CVE-2026-14831 was published on August 6, 2026.