HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-40774Published Modified CNA Patchstack

CVE-2026-40774: WordPress Booking Package plugin <= 1.7.06 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Booking Package <= 1.7.06 versions.

Metrics

CVSS v3.1
7.5
Severity
HIGH
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

Broken access control in the WordPress Booking Package plugin (versions up to and including 1.7.06) allows an unauthenticated remote attacker to perform unauthorized write operations. The vulnerability is reachable over the network with no credentials required and no victim interaction needed, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N). Successful exploitation gives an attacker the ability to tamper with booking data or plugin-managed content, with no patch currently available from the vendor. HarborGuard is tracking the upstream advisory and will make a patched-image rebuild available the moment a fix is published.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds (including Patchstack) within minutes of publication and matched against all customer images, including custom-built WordPress images that bundle the Booking Package plugin. Any image carrying an affected version of the plugin (1.7.06 or earlier) is flagged automatically in the scan pipeline.

Available
Triage

Triage is available with a CVSS score of 7.5 (HIGH severity, v3.1), which HarborGuard surfaces alongside each customer organization's compliance policy weighting to reflect the actual risk in that environment. Findings are routed to the appropriate team inbox based on per-environment ownership rules configured by each customer.

Available
Patch

No fix version has been published for this CVE. HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment the upstream vendor publishes a remediated release. For customers with auto-remediation enabled, the rebuild, regression run, and PR against affected workloads will be initiated without manual intervention once a fix becomes available.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the WordPress site over the network; the vulnerable plugin endpoint is exposed to any remote caller.

  • AuthenticationNot required

    No account or session credentials of any kind are needed to trigger the broken access control flaw.

  • Victim interactionNot required

    The attack is fully server-side and requires no action from any user or administrator of the affected site.

  • Attack complexityDetail

    Exploit conditions are straightforward and reliable, with no race conditions or environmental prerequisites required.

Blast Radius

  • An attacker can make unauthorized writes to booking records or plugin-controlled data, bypassing the access checks that would normally enforce user privilege boundaries.
  • Booking entries, availability settings, or other plugin-managed content can be created, modified, or deleted without any legitimate account.
  • Depending on how the plugin integrates with the broader WordPress installation, tampered booking data may affect downstream business processes such as scheduling, notifications, or payment workflows.

How HarborGuard Handles This

Available on HarborGuard: this CVE is tracked continuously against every scanned image that bundles the Booking Package plugin at version 1.7.06 or earlier, with no configuration required from customers. Because no upstream fix currently exists, HarborGuard re-evaluates the advisory on each ingest cycle. As a compensating control while waiting for a vendor patch, customers can apply WordPress-level network policies or web application firewall rules to restrict access to the plugin's affected endpoints, and can use feature-flag or plugin-disablement options to reduce exposure. The moment the vendor publishes a remediated version, a patched-image rebuild will become available; for customers who opt into auto-remediation, this triggers a rebuild, regression test run, and a PR opened against affected workloads automatically, with no manual steps needed.

See how HarborGuard automates this
Affected packages
  • SaasProject / Booking Package
    ≤ 1.7.06
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
References