CVE-2026-6960: BookingPress Pro <= 5.6 - Unauthenticated Arbitrary File Upload via Signature Custom Field
The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpressvalidatesubmittedbookingformfunc' function in all versions up to, and including, 5.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The vulnerability can only be exploited if a signature custom field is added to the booking form.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6960?
CVE-2026-6960 has a critical severity score of 9.8.
What makes CVE-2026-6960 vulnerable?
CVE-2026-6960 is vulnerable due to missing file type validation, allowing unauthenticated arbitrary file uploads.
What software is affected by CVE-2026-6960?
CVE-2026-6960 affects the BookingPress Pro plugin for WordPress in versions up to and including 5.6.
How do I fix CVE-2026-6960?
To fix CVE-2026-6960, update the BookingPress Pro plugin to the latest version that addresses this vulnerability.
What types of attacks can CVE-2026-6960 facilitate?
CVE-2026-6960 can facilitate attacks involving the upload of malicious files by unauthenticated attackers.