CVE-2026-88995 PUBLISHED

Bookit < 2.6.0.1 - Unauthenticated Appointment PII Disclosure via Availability Check

Assigner: WPScan
Reserved: 10.09.2026 Published: 13.09.2026 Updated: 13.09.2026

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.

Product Status

Vendor Unknown
Product Bookit — Booking & Appointment Calendar
Versions Default: unaffected
  • affected from 0 to 2.6.0.1 (excl.)

Credits

  • Philipp Doblhofer finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE