The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked customer's personal data.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-13 06:17
Updated : 2026-08-26 16:30
NVD link : CVE-2026-14213
Mitre link : CVE-2026-14213
CVE.ORG link : CVE-2026-14213
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
