Unauthorized Access in Bookit Booking & Appointment Calendar Plugin for WordPress
CVE-2026-89008

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 September 2026

Badges

πŸ‘Ύ Exploit Exists🟑 Public PoC

What is CVE-2026-89008?

The Bookit β€” Booking & Appointment Calendar plugin for WordPress prior to version 2.6.0.5 has a critical flaw that bypasses necessary authorization checks on appointment retrieval actions. This defect allows users with lower privileges to access sensitive information belonging to other users, including their names, email addresses, phone numbers, and private comments associated with bookings. It poses a serious risk of data exposure, undermining user privacy and the integrity of appointment management.

Affected Version(s)

Bookit β€” Booking & Appointment Calendar 0 < 2.6.0.5

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Farid Narimanov
WPScan
.