GHSA-2963-vmc7-jqxwLowCVSS 2.7

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a...

Published
September 18, 2026
Last Modified
September 18, 2026

🔗 CVE IDs covered (1)

📋 Description

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one of its appointment-deletion functions, allowing users with its low-privileged custom Staff role to delete arbitrary appointments.

🔗 References (3)