CVE-2026-27389Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Authentication Abuse.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-05); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-05: 1Mentions · 2026-03-12: 1Patch / Workaround · 2026-03-12: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-12: 103-0503-12
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • Quttera - eCommerce Security@MNovofastovsky
    Disclosure

    ⚠️ CVE-2026-27389 exposes #WordPress sites using the WeDesignTech Ultimate Booking Addon (≤1.0.1) to an authentication bypass vulnerability. https://nvd.nist.gov/vuln/detail/CVE-2026-27389 Attackers may exploit alternate access paths to bypass login controls and potentially take over user accounts or admin functionality. Risk: unauthorized access, booking manipulation, and full site compromise. Update or disable the vulnerable plugin immediately and scan your website for hidden backdoors. https://quttera.com/wordpress-malware-scanner #WordPress #CVE #CyberSecurity #WebsiteSecurity #Vulnerability #SilentRisk

    Post summary

    CVE-2026-27389 exposes an authentication bypass in the WeDesignTech Ultimate Booking Addon for WordPress, and users should update or disable the plugin and run malware scans to prevent unauthorized access.

    0000046
    36 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27389 Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows … https://www.cve.org/CVERecord?id=CVE-2026-27389

    Post summary

    CVE-2026-27389 is an authentication‑bypass vulnerability in the WeDesignTech Ultimate Booking Addon, with a brief summary and a link to the official CVE record.

    00000153
    56.6K followersView on X

Explore more