🔐 CVE Alert

CVE-2026-88995

MEDIUM 5.3

Bookit < 2.6.0.1 - Unauthenticated Appointment PII Disclosure via Availability Check

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.

Vendor unknown
Product bookit — booking & appointment calendar
Published Sep 13, 2026
Last Updated Sep 13, 2026
Stay Ahead of the Next One

Get instant alerts for unknown bookit — booking & appointment calendar

Be the first to know when new medium vulnerabilities affecting unknown bookit — booking & appointment calendar are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Bookit — Booking & Appointment Calendar
0 < 2.6.0.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/5a6f6d75-e7b8-44ad-a0f6-f6e4938ac3d5/

Credits

Philipp Doblhofer WPScan