CVE-2026-27389

CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Authentication Abuse.This issue...

Affects 0 products across 2 vendors.

BCS6.43
CVSS 3.19.8
EPSS0.4%
Percentile34th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-288: CWE-288
Related Attack Patterns (CAPEC)
CAPEC-127 Directory Indexing
via CWE-288
CAPEC-665 Exploitation of Thunderbolt Protection Flaws
via CWE-288

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in the WeDesignTech Ultimate Booking Addon allows attackers to bypass authentication through an alternate path or channel, potentially leading to unauthorized access.

BSID: BS-2026-GLOBAL-075889-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-27389?
A critical vulnerability in the WeDesignTech Ultimate Booking Addon allows attackers to bypass authentication through an alternate path or channel, potentially leading to unauthorized access.
What is the CVSS score for CVE-2026-27389?
CVE-2026-27389 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.4%.
Is CVE-2026-27389 actively exploited?
No confirmed active exploitation of CVE-2026-27389 as of 2026-05-30.
How do I remediate CVE-2026-27389?
Priority: IMMEDIATE.
What systems are affected by CVE-2026-27389?
CVE-2026-27389 affects: Abuse, Booking.
Vulnerability Details
CVE IDCVE-2026-27389
BSIDBS-2026-GLOBAL-075889-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2026-03-05
Last Modified2026-04-22
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Authentication Abuse.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.1.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability stems from an improper handling of authentication mechanisms, enabling attackers to exploit an alternate path or channel to gain unauthorized access without proper credentials.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Abuse &mdash;
Booking &mdash;
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 142 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashf604fcd4979b9ecc7bdbc6c48b9f3343296fddec6e4f28bf13c96547b13cc077f6cda5deea8a145f5c466a5954663e1aee88f6cd026485ad3f7f09fa5a2ead96
Related CVEs affecting Abuse
CVE-1999-0512 10.0 A mail server is explicitly configured to allow SMTP mail relay, which allows... CVE-2026-23693 10.0 ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elemen... CVE-2025-4378 10.0 Cleartext Transmission of Sensitive Information, Use of Hard-coded Credential... CVE-2024-28189 10.0 Judge0 is an open-source online code execution system. The application uses t... CVE-2026-40089 9.9 Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. Th...
View all Abuse CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →