Appointment Deletion Flaw in Bookit Booking & Appointment Calendar Plugin by WordPress
CVE-2026-89007
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 September 2026
Badges
πΎ Exploit Existsπ‘ Public PoC
What is CVE-2026-89007?
The Bookit β Booking & Appointment Calendar WordPress plugin, prior to version 2.6.0.5, contains a critical flaw that permits users assigned the low-privileged custom Staff role to delete any appointment without proper capability checks. This deficiency can lead to unauthorized removal of important booking data, presenting a serious risk to organizations relying on this plugin for scheduling. Proper implementation of capability checks is essential to safeguard against such vulnerabilities.
Affected Version(s)
Bookit β Booking & Appointment Calendar 0 < 2.6.0.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.