CVE-2026-14216: Unknown Booking For Appointments And Events Calendar
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.
Affected products
- Unknown Booking For Appointments And Events Calendar: before 2.4.7 (fixed in 2.4.7)
Published 2026-08-26. Last modified 2026-08-26.