Description
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one of its appointment-deletion functions, allowing users with its low-privileged custom Staff role to delete arbitrary appointments.
Published: 2026-09-18
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Deletion
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the Bookit — Booking & Appointment Calendar WordPress plugin versions earlier than 2.6.0.5, where one of the appointment‑deletion functions fails to perform a capability check. This omission allows a user who has the plugin’s low‑privileged Staff role to delete any appointment stored in the system. The deletion can remove scheduled events, disrupt client bookings, and erase billing or history data, thereby compromising the integrity of the booking database. The weakness is an authorization bypass identified as CWE‑862.

Affected Systems

WordPress sites that have the Bookit plugin (Booking & Appointment Calendar) installed with a version prior to 2.6.0.5. The vulnerability is present in every installation that does not upgrade to the patched release, regardless of other security plugins or hardening settings.

Risk and Exploitability

The CVSS base score is 2.7, reflecting a low confidentiality and integrity impact with no availability effect. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the issue is not listed in the CISA KEV catalog. Exploitation would occur via the WordPress admin interface or any exposed REST endpoint that triggers the deletion process; an attacker only needs access to a Staff‑level user account. No additional secrets or privileges are required.

Generated by OpenCVE AI on September 19, 2026 at 19:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Bookit plugin to version 2.6.0.5 or later.
  • If an upgrade is not immediately possible, remove the deletion capability from the Staff role by editing the plugin’s role capabilities or using a role‑management plugin to restrict delete permissions.
  • Continuously audit appointment logs for evidence of unauthorized deletions and monitor staff activity to detect potential abuse.

Generated by OpenCVE AI on September 19, 2026 at 19:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions bookit
Vendors & Products Wordpress-extensions
Wordpress-extensions bookit

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one of its appointment-deletion functions, allowing users with its low-privileged custom Staff role to delete arbitrary appointments.
Title Bookit < 2.6.0.5 - Bookit Staff+ Arbitrary Appointment Deletion via Missing Authorization
References

Subscriptions

Wordpress-extensions Bookit
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-18T11:08:14.184Z

Reserved: 2026-09-10T16:21:54.826Z

Link: CVE-2026-89007

cve-icon Vulnrichment

Updated: 2026-09-18T11:00:36.587Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T06:16:41.477

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-89007

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:50:08Z

Weaknesses