Bookit — Booking & Appointment Calendar WordPress 插件在 2.6.0.5 版本之前的预约删除功能中未进行权限检查,允许拥有低权限自定义 Staff(员工)角色的用户删除任意预约。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Bookit — Booking & Appointment Calendar | < 2.6.0.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Bookit — Booking & Appointment Calendar | 0 ~ 2.6.0.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88994 | 6.6 MEDIUM | All Bootstrap Blocks 1.3.20 - 1.3.31 - Contributor+ LFI via lightspeed Block Attributes |
| CVE-2026-79713 | 6.5 MEDIUM | Breeze Cache 1.2.5 - 2.5.14 - Unauthenticated Cache Poisoning via Unkeyed Tracking Paramet |
| CVE-2026-90977 | 5.3 MEDIUM | Clean Login < 1.19 - Unauthenticated CAPTCHA Bypass via Empty Session Comparison |
| CVE-2026-90976 | 5.3 MEDIUM | Clean Login < 1.19 - Unauthenticated Account Creation with Registration Disabled |
| CVE-2026-86800 | 5.3 MEDIUM | WP Ghost (Hide My WP Ghost) < 7.0.11 - Unauthenticated URL Hiding Bypass via Loopback Comp |
| CVE-2026-86796 | 5.3 MEDIUM | WP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detection and URL Hi |
| CVE-2026-87775 | Tz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQLi via tzwrs_update_cell | |
| CVE-2026-90978 | Filter Gallery < 1.1.5 - Subscriber+ Arbitrary Post Overwrite and Plugin Option Deletion v | |
| CVE-2026-90984 | Generate PDF using Contact Form 7 < 4.2.2 - Unauthenticated Server-Side Request Forgery vi | |
| CVE-2026-89008 | Bookit < 2.6.0.5 - Bookit Staff+ Appointment PII Disclosure | |
| CVE-2026-87966 | Easy Appointments 4.0 - 4.0.2.1 - Unauthenticated Arbitrary Appointment Modification and D | |
| CVE-2026-88825 | iGMS Direct Booking < 2.0 - Unauthenticated Stored XSS via Widget Settings | |
| CVE-2026-88798 | Really Simple Security (Free) < 9.8.3 - Unauthenticated Unbounded Option Growth via Spoofe | |
| CVE-2026-88993 | All Bootstrap Blocks <= 1.3.31 - Contributor+ Stored XSS via areoi/button type Attribute | |
| CVE-2026-88844 | MasterStudy LMS 3.6.2 - < 3.7.50 - Instructor+ Student PII Disclosure via IDOR | |
| CVE-2026-87770 | Price Drop Alert for WooCommerce <= 1.1 - Unauthenticated SQL Injection via product | |
| CVE-2026-81810 | All-in-One WP Migration and Backup < 7.111 - Authenticated Privilege Escalation to Admin v | |
| CVE-2026-87771 | Product Question and Answer <= 1.1.0 - Unauthenticated SQL Injection via p_id and read | |
| CVE-2026-87774 | Tz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQL Injection via week | |
| CVE-2026-87965 | Easy Appointments < 4.0.2.2 - Unauthenticated Appointment Cancellation/Confirmation via Fo |
Showing top 20 of 32 CVEs. View all on vendor page → →
No comments yet