CVE-2026-12113

The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filter_list. This makes it possible for authenticated attackers, with contributor-level access and above, to extract customer names, email addresses, phone numbers, appointment comments, and other booking personally identifiable information.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-01 05:16

Updated : 2026-07-01 13:56


NVD link : CVE-2026-12113

Mitre link : CVE-2026-12113

CVE.ORG link : CVE-2026-12113


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization