---
id: CVE-2026-88995
title: >-
  The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1
  does not properly restrict the data returned by an availability-check request,
  allowing unauthenticated users to retrieve other customers' appointment
  details, i…
summary: >-
  The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1
  does not properly restrict the data returned by an availability-check request,
  allowing unauthenticated users to retrieve other customers' appointment
  details, i…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
product: Bookit — Booking & Appointment Calendar
affected:
  - bookit_booking_appointment_calendar < 2.6.0.1
published: '2026-09-13'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T21:10:17.423'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88995'
references:
  - url: 'https://wpscan.com/vulnerability/5a6f6d75-e7b8-44ad-a0f6-f6e4938ac3d5/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-13T10:41:46.966639Z'
ingestedAt: '2026-09-14T15:23:07.471Z'
epss: 0.00345
epssPercentile: 0.25282
---

## Overview

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
