CVE-2026-12111: Appointment Booking Calendar <= 1.4.01 - Authenticated (Contributor+) Sensitive Information Exposure via 'id' Parameter

Published Jun 18, 2026
·
Updated

The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.4.01. This is due to insufficient authorization and missing per-calendar ownership checks in the cpabcappointmentscalendarload2() function, which is reachable via the cpabccalendarload2=1 query parameter in wp-admin and only checks isadmin() && currentusercan('editposts'), a capability available to Contributor-level users and above. This makes it possible for authenticated attackers with Contributor-level access and above to supply an arbitrary calendar ID via the id parameter and extract customer booking information, including email addresses, names, phone numbers, booking times, and comments, from any calendar managed by the plugin.

Affected Software

1 affected component
Appointment Booking Calendar Appointment Booking Calendar (WordPress plugin)<=1.4.01

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Appointment Booking Calendar (WordPress plugin) from your environment.

    If the plugin is not required, uninstall the Appointment Booking Calendar plugin to eliminate the vulnerable functionality until a fix is available.

  2. Configuration

    Modify cpabc_appointments_calendar_load2() to (1) verify the current user is the owner/manager of the requested calendar ID and (2) replace or augment current_user_can('edit_posts') with a capability limited to administrators or otherwise appropriate roles so Contributor-level users cannot access arbitrary calendar data.

    Appointment Booking Calendar (WordPress plugin) authorization checks in cpabc_appointments_calendar_load2() = enforce per-calendar ownership; require an administrator-only capability instead of current_user_can('edit_posts')
  3. Configuration

    Temporarily remove the 'edit_posts' capability from the Contributor role or restrict assignment of the Contributor role to trusted users until the plugin is fixed, to prevent Contributors from reaching the vulnerable code path.

    WordPress roles/capabilities Contributor 'edit_posts' capability / role assignment = remove or restrict
  4. Compensating control

    Restrict access to wp-admin and the cpabc_calendar_load2 endpoint (and similar plugin management endpoints) to trusted IP addresses via firewall, reverse proxy, or WAF to limit which authenticated users can reach the vulnerable code path.

  5. Operational

    Audit access logs for requests to cpabc_calendar_load2 and any unusual access to calendar IDs; identify potentially exposed customer records (emails, names, phone numbers, booking details), notify affected users as required by policy, and take remedial steps (eg. data retraction or password resets) if sensitive account credentials may have been exposed.

Event History

Jun 18, 2026
CVE Published
via MITRE·06:50 AM
Data Sourced
via MITRE·06:50 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-12111?

The severity of CVE-2026-12111 is medium with a score of 4.3.

2

How do I fix CVE-2026-12111?

To fix CVE-2026-12111, update the Appointment Booking Calendar plugin to version 1.4.02 or later.

3

What type of exposure does CVE-2026-12111 involve?

CVE-2026-12111 involves sensitive information exposure due to insufficient authorization.

4

Which versions of the Appointment Booking Calendar are affected by CVE-2026-12111?

CVE-2026-12111 affects all versions up to and including 1.4.01 of the Appointment Booking Calendar.

5

What functions are related to CVE-2026-12111?

CVE-2026-12111 is related to the cpabc_appointments_calendar_load2() function.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203