Description
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.
Published: 2026-09-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly limit the data returned by an availability‑check request. An unauthenticated attacker can retrieve appointment details of other customers, including free‑text comments and contact information, exposing personally identifiable information to anyone who can access the endpoint. Versions older than 2.6.0.1 are affected. This vulnerability represents a CWE-200 weakness.

Affected Systems

The affected product is the WordPress plugin Bookit — Booking & Appointment Calendar, in versions earlier than 2.6.0.1. Those releases expose appointment data through the availability‑check endpoint to unauthenticated users.

Risk and Exploitability

The vulnerability requires only an unauthenticated HTTP request to the availability‑check endpoint; no authentication or privileged access is needed. Its CVSS score of 5.3 indicates moderate risk. With an EPSS score of 0.00206 and it not appearing in the CISA KEV catalog, there is no evidence of active exploitation, but the ability to read sensitive appointment details can lead to privacy violations and regulatory non‑compliance. The very low EPSS value implies a low probability of exploitation.

Generated by OpenCVE AI on September 15, 2026 at 17:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Bookit plugin to version 2.6.0.1 or later to secure the availability‑check endpoint.
  • Restrict access to the availability‑check endpoint by configuring your web server to allow only authenticated users or to limit requests to trusted IPs.
  • Disable the availability‑check feature in the Bookit settings if the option is available.

Generated by OpenCVE AI on September 15, 2026 at 17:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.
Title Bookit < 2.6.0.1 - Unauthenticated Appointment PII Disclosure via Availability Check
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-13T10:44:21.648Z

Reserved: 2026-09-10T16:07:00.940Z

Link: CVE-2026-88995

cve-icon Vulnrichment

Updated: 2026-09-13T10:41:30.384Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T06:16:25.543

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-88995

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:30:10Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor