CVE-2026-92799 | ladela Online Scheduling and Appointment Booking System Plugin Ajax Controller postValidateCustomer authorization

SecurityVulns

A vulnerability was found in ladela Online Scheduling and Appointment Booking System Plugin up to 28.2 on WordPress. It has been rated as problematic. Impacted is the function postValidateCustomer of the component Ajax Controller. This manipulation of the argument verification_code causes authorization bypass.

This vulnerability appears as CVE-2026-92799. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More