CVE-2026-88995: Bookit < 2.6.0.1 - Unauthenticated Appointment PII Disclosure via Availability Check
Published Sep 13, 2026
·Updated
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.
Affected Software
1 affected component
WordPress plugin Bookit — Booking & Appointment Calendar<2.6.0.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bookit — Booking & Appointment Calendar WordPress pluginto a version that resolves this vulnerability.Fixed in 2.6.0.1
Event History
Sep 13, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Which sites are affected?
WordPress sites using the Bookit — Booking & Appointment Calendar plugin in versions earlier than 2.6.0.1 are affected.
2
Does exploitation require authentication?
No. An unauthenticated user can issue an availability-check request and retrieve other customers' appointment details.