CVE-2026-84767: WordPress BookIt plugin <= 2.6.0.3 - Bypass Vulnerability vulnerability
Published Sep 3, 2026
·Updated
Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.
Affected Software
1 affected component
WordPress BookIt plugin<=2.6.0.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress BookIt Pluginto a version that resolves this vulnerability.Fixed in 2.6.0.4
Event History
Sep 3, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior privileges to attempt exploitation. Network access to the affected BookIt plugin is indicated by the AV:N vector.
2
Which versions are affected?
BookIt versions 2.6.0.3 and earlier are identified as affected. The provided information does not identify a fixed version.
3
What security impact is indicated?
The severity vector indicates low integrity impact and no stated confidentiality or availability impact. It is rated medium with a CVSS score of 5.3.