Unauthorized Data Modification in Booktics - Booking Calendar for Appointments and Service Businesses by WordPress
CVE-2026-11446
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 September 2026
What is CVE-2026-11446?
The Booktics β Booking Calendar for Appointments and Service Businesses plugin for WordPress has a vulnerability allowing unauthorized modifications of customer data. The issue arises from the create_order_permission() function, which lacks proper authentication checks. This flaw permits unauthenticated attackers to overwrite the contact details, such as name and phone number, of any existing customer if they know the email address. This unauthorized access can lead to the alteration of critical customer information, impacting downstream communications like automated reminders and customer relationship management (CRM) data.
Affected Version(s)
Booktics β Appointment Booking Calendar for Service Businesses 0 <= 1.0.23