MEDIUM
CVE-2026-88995
CVSS
5.3
Description
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.
Weakness (CWE)
CWE-200
Information Exposure
EPSS Score
0.21%
Probability of exploitation in next 30 days
11.1th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.