CVE-2026-39678: WordPress Pinpoint Booking System plugin <= 2.9.9.6.5 - Broken Access Control vulnerability
Published Apr 8, 2026
·Updated
Missing Authorization vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pinpoint Booking System: from n/a through <= 2.9.9.6.5.
Affected Software
1 affected component
Dotonpaper Pinpoint Booking System<=2.9.9.6.5
Event History
Apr 8, 2026
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39678?
CVE-2026-39678 has a medium severity rating of 5.3.
2
How do I fix CVE-2026-39678?
To fix CVE-2026-39678, update the DotOnPaper Pinpoint Booking System plugin to a version later than 2.9.9.6.5.
3
What type of vulnerability is CVE-2026-39678?
CVE-2026-39678 is a Broken Access Control vulnerability.
4
Which versions of Pinpoint Booking System are affected by CVE-2026-39678?
CVE-2026-39678 affects Pinpoint Booking System versions from n/a through 2.9.9.6.5.
5
What impact does CVE-2026-39678 have on security?
CVE-2026-39678 allows attackers to exploit incorrectly configured access control security levels.