CVE-2026-62101: WordPress EduAdmin Booking plugin <= 5.4.2 - Broken Authentication vulnerability
Published Sep 17, 2026
·Updated
Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.
Affected Software
1 affected component
WordPress EduAdmin Booking plugin<=5.4.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress EduAdmin Booking Pluginto a version that resolves this vulnerability.Fixed in 6.0.0
Event History
Sep 17, 2026
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior access to the site. The vector is network-based and requires low attack complexity, with no user interaction required.
2
Which plugin versions are affected?
EduAdmin Booking versions 5.4.2 and earlier are affected according to the available data.
3
What impact could successful exploitation have?
The supplied severity vector indicates potential high impact to confidentiality, integrity, and availability. The vulnerability is rated critical with a CVSS score of 9.8.