CVE-2026-88995
Bookit < 2.6.0.1 - Unauthenticated Appointment PII Disclosure via Availability Check
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.
| Vendor | unknown |
| Product | bookit — booking & appointment calendar |
| Published | Sep 13, 2026 |
| Last Updated | Sep 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown bookit — booking & appointment calendar
Be the first to know when new medium vulnerabilities affecting unknown bookit — booking & appointment calendar are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Bookit — Booking & Appointment Calendar
0 < 2.6.0.1
References
Credits
Philipp Doblhofer WPScan