
⚠️ CVE-2026-27389 exposes #WordPress sites using the WeDesignTech Ultimate Booking Addon (≤1.0.1) to an authentication bypass vulnerability. https://nvd.nist.gov/vuln/detail/CVE-2026-27389 Attackers may exploit alternate access paths to bypass login controls and potentially take over user accounts or admin functionality. Risk: unauthorized access, booking manipulation, and full site compromise. Update or disable the vulnerable plugin immediately and scan your website for hidden backdoors. https://quttera.com/wordpress-malware-scanner #WordPress #CVE #CyberSecurity #WebsiteSecurity #Vulnerability #SilentRisk
Post summary
CVE-2026-27389 exposes an authentication bypass in the WeDesignTech Ultimate Booking Addon for WordPress, and users should update or disable the plugin and run malware scans to prevent unauthorized access.

