CVE-2026-88995: Unknown Bookit — Booking & Appointment Calendar

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.

Affected products

  • Unknown Bookit — Booking & Appointment Calendar: before 2.6.0.1 (fixed in 2.6.0.1)

Published 2026-09-13. Last modified 2026-09-14.