Unauthorized Access in Bookit Booking & Appointment Calendar Plugin for WordPress
CVE-2026-89008
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 September 2026
Badges
What is CVE-2026-89008?
The Bookit β Booking & Appointment Calendar plugin for WordPress prior to version 2.6.0.5 has a critical flaw that bypasses necessary authorization checks on appointment retrieval actions. This defect allows users with lower privileges to access sensitive information belonging to other users, including their names, email addresses, phone numbers, and private comments associated with bookings. It poses a serious risk of data exposure, undermining user privacy and the integrity of appointment management.
Affected Version(s)
Bookit β Booking & Appointment Calendar 0 < 2.6.0.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.