Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-88995

Опубликовано: 13 сент. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.

EPSS

Процентиль: 11%
0.00206
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
github
10 дней назад

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.

EPSS

Процентиль: 11%
0.00206
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200