CVE-2026-6960
WordPress BookingPress plugin allows attackers to upload harmful files enabling remote control
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
The BookingPress Pro WordPress plugin has a flaw allowing attackers to upload any file, potentially giving them control of your website's server. This is a critical risk for sites using booking forms with a signature field.