Description
The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple REST API endpoints in all versions up to, and including, 1.0.16. This makes it possible for unauthenticated attackers to query sensitive data.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 10 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arraytics
Arraytics booktics – Booking Calendar For Appointments And Service Businesses Wordpress Wordpress wordpress |
|
| Vendors & Products |
Arraytics
Arraytics booktics – Booking Calendar For Appointments And Service Businesses Wordpress Wordpress wordpress |
Tue, 10 Mar 2026 02:45:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-03-10T16:52:18.141Z
Reserved: 2026-02-04T16:38:59.005Z
Link: CVE-2026-1919
Updated: 2026-03-10T15:58:08.298Z
Status : Awaiting Analysis
Published: 2026-03-10T17:32:45.850
Modified: 2026-03-11T13:53:47.157
Link: CVE-2026-1919
No data.
OpenCVE Enrichment
Updated: 2026-03-10T14:06:04Z
Weaknesses