Arbitrary File Upload Vulnerability in BookingPress Pro by WordPress
⚠️ CVE-Referenzen:
CVE-2026-6960
WordPress - Bookingpress Appointment Booking Pro - CRITICAL - CVE-2026-6960.
The BookingPress Pro plugin for WordPress contains a vulnerability that allows for arbitrary file uploads due to inadequate file type validation in the 'bookingpress_validate_submitted_booking_form_func' function. This vulnerability affects all versions up to and including 5.6. Without proper safeguards, unauthenticated attackers can exploit this flaw to upload arbitrary files to the server, potentially enabling remote code execution. Exploitation is contingent upon the inclusion of a signature custom field in the booking form, making it crucial for site administrators to apply necessary patches and upgrade to secure versions.
Quelle: securityvulnerability.io