PT-2026-42552 · WordPress · Bookingpress Pro
Published
2026-05-21
·
Updated
2026-05-23
·
CVE-2026-6960
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BookingPress Pro versions prior to 5.7
Description
The BookingPress Pro plugin for WordPress allows unauthenticated attackers to upload arbitrary files to the server, which may lead to remote code execution. This occurs due to missing file type validation within the
bookingpress validate submitted booking form func() function. Exploitation is only possible if a signature custom field has been added to the booking form.Recommendations
Update to a version later than 5.6.
As a temporary workaround, remove the signature custom field from the booking form to prevent exploitation.
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bookingpress Pro