CVE-2026-88995
EUVD-2026-7695813.09.2026, 06:16
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.