CVE-2026-27405: WordPress WpBookingly plugin <= 1.2.9 - Broken Access Control vulnerability
Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects WpBookingly: from n/a through 1.2.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WpBookingly pluginto a version that resolves this vulnerability.Fixed in 1.3.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27405?
CVE-2026-27405 is categorized as a broken access control vulnerability, which can lead to unauthorized access to sensitive resources.
How do I fix CVE-2026-27405?
To fix CVE-2026-27405, update the WpBookingly plugin to the latest version beyond 1.2.9 that patches the access control vulnerability.
What versions of WpBookingly are affected by CVE-2026-27405?
CVE-2026-27405 affects WpBookingly plugin versions up to and including 1.2.9.
What are the potential risks of CVE-2026-27405?
The risks of CVE-2026-27405 include unauthorized actions and exposure of sensitive information due to inadequate access control.
Is CVE-2026-27405 exploitable by remote attackers?
Yes, CVE-2026-27405 can be exploited by remote attackers if they find ways to bypass the inadequate access controls.