{"id":"CVE-2026-89007","title":"The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one of its appointment-deletion functions, allowing users with its low-privileged custom Staff role to delete arbitrary ap…","summary":"The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one of its appointment-deletion functions, allowing users with its low-privileged custom Staff role to delete arbitrary ap…","severity":"low","cvss":2.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-862"],"product":"Bookit — Booking & Appointment Calendar","affected":["bookit_booking_appointment_calendar < 2.6.0.5"],"published":"2026-09-18","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:08:32.830","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89007","references":[{"url":"https://wpscan.com/vulnerability/5e174229-a375-456c-b651-7ad4a3c004ab/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"epss":0.00168,"epssPercentile":0.0655,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-18T11:00:52.446747Z"},"ingestedAt":"2026-09-18T06:36:37.987Z","slug":"CVE-2026-89007","body":"## Overview\n\nThe Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one of its appointment-deletion functions, allowing users with its low-privileged custom Staff role to delete arbitrary appointments.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":15,"depthScoreParts":{"impact":14.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":206761,"id":"CVE-2026-89007","ts":1789731639495,"field":"cvss","old":null,"new":"2.7"},{"seq":206760,"id":"CVE-2026-89007","ts":1789731639495,"field":"severity","old":"none","new":"low"}]}