CVE-2026-15229: Unknown Pinpoint Booking System

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation.

Affected products

  • Unknown Pinpoint Booking System: up to and including 2.9.9.7.1

Published 2026-08-10. Last modified 2026-08-26.