Loading market data...
← Back to CVE feed

CVE-2026-14213

LOW CVSS 3.7 View on NVD ↗

Description

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked customer's personal data.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Published: Aug 13, 2026 06:17 UTC Modified: Aug 13, 2026 15:19 UTC