Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h8fj-8c8p-pcww

Опубликовано: 13 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.

EPSS

Процентиль: 11%
0.00206
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
nvd
10 дней назад

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.

EPSS

Процентиль: 11%
0.00206
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200