CVE-2026-88995
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.
- Published Sep 13, 2026
- CVSS 5.3 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available