CVE-2026-89008: Bookit < 2.6.0.5 - Bookit Staff+ Appointment PII Disclosure
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on one of its appointment-retrieval actions, allowing users with a low-privilege Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5-specific role to read other users' appointment records, including customer names, email addresses, phone numbers and private booking comments.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A user needs a low-privilege role specific to the Bookit plugin. The issue allows that role to retrieve appointment records belonging to other users.
What information could be exposed?
Exposed appointment records can include customer names, email addresses, phone numbers, and private booking comments.
Which versions are affected?
Bookit — Booking & Appointment Calendar versions before 2.6.0.5 are affected. Upgrading to 2.6.0.5 or later addresses the affected version range described.