CVE-2026-28159: WordPress Service Finder Booking plugin <= 6.2 - Broken Access Control vulnerability
Published Aug 13, 2026
·Updated
Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.
Affected Software
1 affected component
WordPress Service Finder Booking plugin<=6.2
Event History
Aug 13, 2026
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-28159?
The severity of CVE-2026-28159 is medium, with a score of 6.5.
2
What does CVE-2026-28159 affect?
CVE-2026-28159 affects the WordPress Service Finder Booking plugin version 6.2 and earlier.
3
How do I fix CVE-2026-28159?
To fix CVE-2026-28159, you should update the Service Finder Booking plugin to version 6.3 or later.
4
What type of vulnerability is CVE-2026-28159?
CVE-2026-28159 is identified as a Broken Access Control vulnerability.
5
Who is impacted by CVE-2026-28159?
Users with Subscriber roles can be impacted due to the broken access control in Service Finder Booking plugin.