Loading market data...
← Back to CVE feed

CVE-2026-14216

MEDIUM CVSS 6.5 View on NVD ↗

Description

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Published: Aug 26, 2026 06:16 UTC Modified: Aug 26, 2026 16:30 UTC