Unrated severityNVD Advisory· Published Sep 13, 2026
CVE-2026-88995
CVE-2026-88995
Description
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<2.6.0.1+ 1 more
- (no CPE)range: <2.6.0.1
- (no CPE)range: <2.6.0.1
Package: https://wordpress.org/plugins/bookit
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.