{"api_version":"1","generated_at":"2026-08-10T11:35:19+00:00","cve":"CVE-2026-15229","urls":{"html":"https://cve.report/CVE-2026-15229","api":"https://cve.report/api/cve/CVE-2026-15229.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-15229","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-15229"},"summary":{"title":"Pinpoint Booking System <= 2.9.9.6.9 - Unauthenticated Arbitrary Booking Price Manipulation","description":"The Pinpoint Booking System  WordPress plugin through 2.9.9.6.9 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-08-10 07:16:47","updated_at":"2026-08-10 07:16:47"},"problem_types":["CWE-863 Incorrect Authorization"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/be12c266-dee7-463d-ae71-9f7b7e0258ee/","name":"https://wpscan.com/vulnerability/be12c266-dee7-463d-ae71-9f7b7e0258ee/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-15229","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15229","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Pinpoint Booking System","version":"affected 2.9.9.6.9 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Ahmed Hashim Ismael","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unknown","product":"Pinpoint Booking System","vendor":"Unknown","versions":[{"lessThanOrEqual":"2.9.9.6.9","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Ahmed Hashim Ismael"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Pinpoint Booking System  WordPress plugin through 2.9.9.6.9 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation."}],"problemTypes":[{"descriptions":[{"description":"CWE-863 Incorrect Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-10T06:00:17.447Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/be12c266-dee7-463d-ae71-9f7b7e0258ee/"}],"source":{"discovery":"EXTERNAL"},"title":"Pinpoint Booking System <= 2.9.9.6.9 - Unauthenticated Arbitrary Booking Price Manipulation","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-15229","datePublished":"2026-08-10T06:00:17.447Z","dateReserved":"2026-07-09T11:07:35.406Z","dateUpdated":"2026-08-10T06:00:17.447Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-10 07:16:47","lastModifiedDate":"2026-08-10 07:16:47","problem_types":["CWE-863 Incorrect Authorization"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"15229","Ordinal":"1","Title":"Pinpoint Booking System <= 2.9.9.6.9 - Unauthenticated Arbitrary","CVE":"CVE-2026-15229","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"15229","Ordinal":"1","NoteData":"The Pinpoint Booking System  WordPress plugin through 2.9.9.6.9 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation.","Type":"Description","Title":"Pinpoint Booking System <= 2.9.9.6.9 - Unauthenticated Arbitrary"}]}}}