AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-14213

LOW · CVSS 3.7 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Booking for Appointments and Events Calendar plugin for WordPress prior to version 2.4.6 is vulnerable due to a lack of verification for authenticated employees accessing appointment details, enabling unauthorized access to sensitive customer information. This flaw poses a significant risk of personal data exposure, making it critical for organizations using this plugin to prioritize updates to mitigate potential data breaches. WordPress site administrators and those managing appointment-related functionalities should address this vulnerability promptly.

CVE
CVE-2026-14213
Severity
LOW
CVSS
3.7
EPSS
0.16%
WordPress

Original NVD Description

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked customer's personal data.