CVE-2026-6960Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in all versions up to, and including, 5.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The vulnerability can only be exploited if a signature custom field is added to the booking form.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-22); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-21: 1Mentions · 2026-05-22: 2Mentions · 2026-05-23: 1Patch / Workaround · 2026-05-21: 1Technical Details · 2026-05-21: 1Technical Details · 2026-05-22: 2Technical Details · 2026-05-23: 105-2105-2205-23
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-211
Patch1
2026-05-222
Disclosure2
2026-05-231
Disclosure1
Full discourse4 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-6960 — CVSS 9.8/10 ██████████ The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/IXFnFj3VEG

    Post summary

    The tweet alerts that BookingPress Pro for WordPress suffers from a critical CVE (arbitrary file upload) and that a patch is now available.

    10000195
    43 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 THREE WordPress plugins, THREE critical 9.8 CVSS vulnerabilities, all unauthenticated. 🔴 Avada Builder (CVE-2026-6279) 🔴 Divi Form Builder (CVE-2026-5118) 🔴 BookingPress Pro (CVE-2026-6960) 🔗 https://threataft.com/articles/wordpress-triple-threat-9-8-cvss-avada-divi-bookingpress #CyberSecurity #WordPress #CVE20266279 #CVE20265118

    Post summary

    A tweet announces that three WordPress plugins—Avada Builder, Divi Form Builder, and BookingPress Pro—contain critical 9.8‑CVSS unauthenticated vulnerabilities.

    00000261
    26 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6960 The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_fo… https://www.cve.org/CVERecord?id=CVE-2026-6960 ----- Traducción: CVE-2026-6960 El … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑6960, revealing that the BookingPress Pro plugin allows arbitrary file uploads because it lacks file‑type validation; no PoC, exploit code, patch, or evidence of active exploitation is provided.

    0000045
    79 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6960 The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_fo… https://www.cve.org/CVERecord?id=CVE-2026-6960

    Post summary

    The post announces CVE‑2026‑6960 affecting BookingPress Pro, highlighting arbitrary file upload flaws due to missing file type validation, with no exploit or patch details provided.

    00000190
    57.5K followersView on X

Explore more