CVE-2026-14216

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-26 06:16

Updated : 2026-08-26 16:30


NVD link : CVE-2026-14216

Mitre link : CVE-2026-14216

CVE.ORG link : CVE-2026-14216


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication