CVE-2026-4911Disclosure

MEDIUMCVSS 5.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The Booking Package plugin for WordPress is vulnerable to Price Manipulation in versions up to, and including, 1.7.06 This is due to the intentForStripe() function passing user-controlled $_POST['amount'] directly to the Stripe PaymentIntent API without validation, and the commitStripe() function ignoring the server-calculated amount when confirming the payment. While the server correctly calculates the booking cost via getAmount() based on services, guests, taxes, and coupons, this calculated amount is never validated against or used to update the PaymentIntent because the critical code in CreditCard.php that would include the calculated amount in the PaymentIntent update is commented out. This makes it possible for unauthenticated attackers to book services at arbitrary prices (e.g., $0.01 instead of $500.00) by manipulating the amount parameter during PaymentIntent creation and completing the booking with the fraudulent payment.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-472

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-28); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-28: 1Mentions · 2026-04-29: 1Mentions · 2026-05-28: 1Active Exploitation · 2026-04-29: 1Patch / Workaround · 2026-05-28: 1Technical Details · 2026-04-28: 1Technical Details · 2026-05-28: 104-2804-2905-28
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-281
Disclosure1
2026-04-291
Active Exploitation1
2026-05-281
Disclosure1
Full discourse3 posts
  • Security Arsenal, LLC@SecurityAr58409
    Disclosure

    🔒 #CyberSecurity CVE-2026-4911, CVE-2026-5502, CVE-2026-1108: CISA KEV Alert — Analysis, Detecti… "CISA adds critical RCE and privilege escalation flaws in Fortinet, Progress Software, and…" 🔗 https://securityarsenal.com/blog/cve-2026-4911-cve-2026-5502-cve-2026-1108-cisa-kev-alert-analysis-detection-and-patching #CyberSecurity #ThreatIntel #cve #zeroday #patchtuesday

    Post summary

    The tweet announces a CISA KEV alert for several CVEs, giving only high‑level details of critical RCE and privilege escalation issues, with a brief nod to detection and patching, but no PoC or active exploit information.

    0000064
    16 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting masaakitanaka Booking Package Plugin (CVE-2026-4911) https://vuldb.com/vuln/359931/cti

    Post summary

    The post reports that offensive activities are targeting CVE-2026‑4911, indicating active exploitation, but it lacks technical details, PoC references, or patch information.

    0000050
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4911 Price Manipulation in Booking Package Plugin for WordPress Versions Up to 1.7.06 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4911

    Post summary

    The text notes a price‑manipulation vulnerability in WordPress's Booking Package Plugin (CVE‑2026‑4911) with affected versions specified, but offers no PoC, exploit code, active exploitation claim, or remediation details.

    0000033
    4.0K followersView on X

Explore more