Sensitive Information Exposure in Booking Calendar Plugin for WordPress
CVE-2026-18496
5.3MEDIUM
What is CVE-2026-18496?
The Booking Calendar plugin for WordPress contains a vulnerability that allows unauthenticated attackers to access sensitive customer information, such as names, email addresses, and phone numbers, through a flaw in the wpbc_is_show_popover_in_flex_timeline() function. All versions up to and including 11.4.3 are impacted, posing a significant risk to user data privacy. This vulnerability highlights the importance of regular updates and security best practices for WordPress plugins.
Affected Version(s)
Booking Calendar 0 <= 11.4.3