Bookit — Booking & Appointment Calendar vulnerability

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.

Published 13 Sep 2026Updated 13 Sep 20261 sources
CVSS 5.3

Source timeline

CVE record published by NVDView source ↗