The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
This vulnerability affects the Appointment Booking Calendar Plugin and Scheduling Plugin for WordPress (versions before 1.6.3), allowing unauthenticated attackers to exploit a critical payment validation flaw. When users complete online payments for appointments, the plugin fails to verify that the amount actually paid matches the server-side price for the booking. This means an attacker can manipulate the payment amount, approve a paid appointment for a fraction of its legitimate cost, or potentially for free. Small businesses, service providers, and organizations relying on this plugin for appointment scheduling and payment collection are directly impacted, facing revenue loss and potential fraud at scale.
While this CVE lacks explicit MITRE ATT&CK technique mapping, Casky's Claude-powered analysis would identify this as a business logic vulnerability pattern consistent with T1190 (Exploit Public-Facing Application) and potentially T1078 (Valid Accounts) techniques when attackers bypass authentication requirements. Practitioners using Casky would observe detection patterns focused on payment confirmation anomalies: requests where client-side payment amounts diverge from server-side expectations, missing or inconsistent price validation in API responses, and approval confirmations lacking cryptographic proof-of-payment verification. Extended reasoning capabilities would flag the absence of server-side validation as a foundational weakness, helping security teams understand that this is not merely a coding error but a fundamental architectural gap in the payment confirmation workflow that requires immediate compensating controls or patching.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-76586. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation