Description
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on one of its appointment-retrieval actions, allowing users with a low-privilege Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5-specific role to read other users' appointment records, including customer names, email addresses, phone numbers and private booking comments.
Published: 2026-09-18
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive personal data exposure
Action: Upgrade
AI Analysis

Impact

The Bookit – Booking & Appointment Calendar WordPress plugin before version 2.6.0.5 contains a missing authorization check on an appointment‑retrieval endpoint, which enables users who possess a low‑privilege plugin‑defined role to retrieve appointment records for other users. The exposed records include customer names, email addresses, phone numbers and private booking comments, which constitutes a protection‑of‑information violation (CWE‑200). While the vulnerability does not provide remote code execution or a denial‑of‑service vector, it allows unauthorized read access to personal data, presenting a privacy and compliance risk.

Affected Systems

Any WordPress site that installs Bookit – Booking & Appointment Calendar prior to version 2.6.0.5 is vulnerable. The specific product is the plugin itself; no particular sub‑components are singled out beyond the appointment‑retrieval action. Sites using any earlier release, regardless of the number of appointments, are at risk of exposing customer personal data to users with the restricted role.

Risk and Exploitability

The CVSS score of 2.7 indicates a low‑severity information disclosure scenario. The EPSS score is reported as less than 1 %, which suggests a very low probability that the vulnerability is actively exploited in the wild. The vulnerability is not listed in the CISA KEV catalog, further indicating limited exploitation. The likely attack vector is the same internal, authenticated route used by the plugin to fetch appointment data; an attacker only needs to be logged in and possess the vulnerable role to trigger the flaw. The missing authorization check means no additional privileges or technical steps are required beyond normal plugin usage.

Generated by OpenCVE AI on September 19, 2026 at 19:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Bookit plugin version 2.6.0.5 or newer to patch the vulnerability
  • Revoke or restrict the low‑privilege Bookit role from accessing the appointment‑retrieval endpoint if the role is no longer needed
  • Enable or review audit logs for appointment access and monitor for any unauthorized reads by users with the low‑privilege role

Generated by OpenCVE AI on September 19, 2026 at 19:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions bookit
Vendors & Products Wordpress-extensions
Wordpress-extensions bookit

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on one of its appointment-retrieval actions, allowing users with a low-privilege Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5-specific role to read other users' appointment records, including customer names, email addresses, phone numbers and private booking comments.
Title Bookit < 2.6.0.5 - Bookit Staff+ Appointment PII Disclosure
References

Subscriptions

Wordpress-extensions Bookit
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-18T11:07:59.693Z

Reserved: 2026-09-10T16:21:58.314Z

Link: CVE-2026-89008

cve-icon Vulnrichment

Updated: 2026-09-18T11:00:21.359Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T06:16:41.597

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-89008

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:50:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor