SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-14215

MEDIUM · CVSS 6.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Booking for Appointments and Events Calendar plugin for WordPress versions prior to 2.4.9 is vulnerable due to a lack of authentication and request token validation, enabling unauthenticated users to exploit the post-booking action chain. This vulnerability allows attackers to trigger booking notifications and integration callbacks by simply enumerating booking identifiers, potentially leading to unauthorized access and information disclosure. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk.

CVE
CVE-2026-14215
Severity
MEDIUM
CVSS
6.5
EPSS
0.30%
WordPress

Original NVD Description

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action chain, allowing an unauthenticated user to trigger booking notifications and integration callbacks for a booking by enumerating its identifier.