CVE-2026-15229: Pinpoint Booking System <= 2.9.9.6.9 - Unauthenticated Arbitrary Booking Price Manipulation
The Pinpoint Booking System WordPress plugin through 2.9.9.6.9 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15229?
CVE-2026-15229 has a risk score of 52, indicating a significant vulnerability affecting the Pinpoint Booking System.
How do I fix CVE-2026-15229?
To fix CVE-2026-15229, update the Pinpoint Booking System WordPress plugin to version 2.9.9.7 or later.
What are the potential impacts of CVE-2026-15229?
CVE-2026-15229 allows unauthenticated users to manipulate booking prices, leading to unauthorized reservations.
Who is affected by CVE-2026-15229?
CVE-2026-15229 affects all users of the Pinpoint Booking System plugin version 2.9.9.6.9 and below.
Is user authentication required to exploit CVE-2026-15229?
No, CVE-2026-15229 can be exploited by unauthenticated users.