Bookit — Booking & Appointment Calendar WordPress 插件在 2.6.0.5 版本之前未对其预约检索动作执行授权检查,使得拥有低权限的“Bookit — Booking & Appointment Calendar”特定角色的用户能够读取其他用户的预约记录,包括客户姓名、电子邮箱地址、电话号码以及私人预订备注。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Bookit — Booking & Appointment Calendar | < 2.6.0.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Bookit — Booking & Appointment Calendar | 0 ~ 2.6.0.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88994 | 6.6 MEDIUM | All Bootstrap Blocks 1.3.20 - 1.3.31 - Contributor+ LFI via lightspeed Block Attributes |
| CVE-2026-79713 | 6.5 MEDIUM | Breeze Cache 1.2.5 - 2.5.14 - Unauthenticated Cache Poisoning via Unkeyed Tracking Paramet |
| CVE-2026-90977 | 5.3 MEDIUM | Clean Login < 1.19 - Unauthenticated CAPTCHA Bypass via Empty Session Comparison |
| CVE-2026-90976 | 5.3 MEDIUM | Clean Login < 1.19 - Unauthenticated Account Creation with Registration Disabled |
| CVE-2026-86800 | 5.3 MEDIUM | WP Ghost (Hide My WP Ghost) < 7.0.11 - Unauthenticated URL Hiding Bypass via Loopback Comp |
| CVE-2026-86796 | 5.3 MEDIUM | WP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detection and URL Hi |
| CVE-2026-87775 | Tz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQLi via tzwrs_update_cell | |
| CVE-2026-90978 | Filter Gallery < 1.1.5 - Subscriber+ Arbitrary Post Overwrite and Plugin Option Deletion v | |
| CVE-2026-90984 | Generate PDF using Contact Form 7 < 4.2.2 - Unauthenticated Server-Side Request Forgery vi | |
| CVE-2026-89007 | Bookit < 2.6.0.5 - Bookit Staff+ Arbitrary Appointment Deletion via Missing Authorization | |
| CVE-2026-87966 | Easy Appointments 4.0 - 4.0.2.1 - Unauthenticated Arbitrary Appointment Modification and D | |
| CVE-2026-88825 | iGMS Direct Booking < 2.0 - Unauthenticated Stored XSS via Widget Settings | |
| CVE-2026-88798 | Really Simple Security (Free) < 9.8.3 - Unauthenticated Unbounded Option Growth via Spoofe | |
| CVE-2026-88993 | All Bootstrap Blocks <= 1.3.31 - Contributor+ Stored XSS via areoi/button type Attribute | |
| CVE-2026-88844 | MasterStudy LMS 3.6.2 - < 3.7.50 - Instructor+ Student PII Disclosure via IDOR | |
| CVE-2026-87770 | Price Drop Alert for WooCommerce <= 1.1 - Unauthenticated SQL Injection via product | |
| CVE-2026-81810 | All-in-One WP Migration and Backup < 7.111 - Authenticated Privilege Escalation to Admin v | |
| CVE-2026-87771 | Product Question and Answer <= 1.1.0 - Unauthenticated SQL Injection via p_id and read | |
| CVE-2026-87774 | Tz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQL Injection via week | |
| CVE-2026-87965 | Easy Appointments < 4.0.2.2 - Unauthenticated Appointment Cancellation/Confirmation via Fo |
Showing top 20 of 32 CVEs. View all on vendor page → →
No comments yet