CVE-2026-1919: Booktics <= 1.0.16 - Missing Authorization to Get Items via REST API endpoints
The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple REST API endpoints in all versions up to, and including, 1.0.16. This makes it possible for unauthenticated attackers to query sensitive data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1919?
CVE-2026-1919 is considered a medium severity vulnerability due to the potential for unauthorized access to sensitive data.
How do I fix CVE-2026-1919?
To fix CVE-2026-1919, you should update the Booktics plugin to version 1.0.17 or later where the missing authorization checks are addressed.
What versions of Booktics are affected by CVE-2026-1919?
CVE-2026-1919 affects all versions of the Booktics plugin up to and including version 1.0.16.
What type of vulnerability is CVE-2026-1919?
CVE-2026-1919 is a missing authorization vulnerability that allows unauthorized access to data through REST API endpoints.
Is there a possibility of data breach from CVE-2026-1919?
Yes, CVE-2026-1919 could lead to a data breach as it may allow unauthorized users to access sensitive information stored in the Booktics application.