CVE-2026-14211

Summary

The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating sequential identifiers.

Affected Software

VendorProductVersion RangeStatus
UnknownBooking for Appointments and Events Calendar9.0 < 9.7affected

Weaknesses

  • CWE-639 Authorization Bypass Through User-Controlled Key

References