CVE-2026-25444: WordPress WpBookingly plugin <= 1.2.9 - Broken Access Control vulnerability
Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects WpBookingly: from n/a through 1.2.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WpBookingly pluginto a version that resolves this vulnerability.Fixed in 1.3.0 - Compensating control
If you cannot immediately update, mitigate the Broken Access Control risk in WordPress by restricting access to WpBookingly-related endpoints/functions to authorized users only (e.g., via WordPress role permissions and/or web access controls) until the plugin is updated to at least 1.3.0.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25444?
CVE-2026-25444 has a medium severity rating of 4.3.
What does CVE-2026-25444 affect?
CVE-2026-25444 affects the WordPress WpBookingly plugin version 1.2.9 and earlier.
How do I fix CVE-2026-25444?
To fix CVE-2026-25444, update the WordPress WpBookingly plugin to version 1.3.0 or later.
What type of vulnerability is CVE-2026-25444?
CVE-2026-25444 is classified as a Broken Access Control vulnerability.
Who is the vendor for CVE-2026-25444?
The vendor for CVE-2026-25444 is MagePeople, the developers of the WpBookingly plugin.