---
id: CVE-2026-15229
title: >-
  The Pinpoint Booking System  WordPress plugin through 2.9.9.6.9 does not
  validate the booking price on the server side, allowing unauthenticated users
  to create bookings at an arbitrary price (including zero) and, by selecting a
  specific…
summary: >-
  The Pinpoint Booking System  WordPress plugin through 2.9.9.6.9 does not
  validate the booking price on the server side, allowing unauthenticated users
  to create bookings at an arbitrary price (including zero) and, by selecting a
  specific…
severity: none
published: '2026-08-10'
updated: '2026-08-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15229'
references:
  - url: 'https://wpscan.com/vulnerability/be12c266-dee7-463d-ae71-9f7b7e0258ee/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-08-10T07:39:17.687Z'
epss: 0.00304
epssPercentile: 0.20515
---

## Overview

The Pinpoint Booking System  WordPress plugin through 2.9.9.6.9 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
