rootpwn

low · CVSS v3 2.7 · EPSS 0.00139

CVE-2026-89008

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on o…

Description

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on one of its appointment-retrieval actions, allowing users with a low-privilege Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5-specific role to read other users' appointment records, including customer names, email addresses, phone numbers and private booking comments.

Scores

Severity
low
CVSS v2
3.3
CVSS v3
2.7
CVSS v4
EPSS
0.00139

← All CVEs