THREAT OPS › Threat News › [NVD] CVE-2026-88995 (MEDIUM 5.3) — The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and con
[NVD] CVE-2026-88995 (MEDIUM 5.3) — The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and con
CVE-2026-88995 CVSS: 5.3 MEDIUM Published: 2026-09-13T06:16:25.543
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.
Indicators of compromise
- CVE-2026-88995cve
- 2.6.0.1ipv4
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-88995