CVE-2025-14982 - Booking Calendar <= 10.14.11 - missing authorization to sensitive information ex...

CVE-2025-14982 - Booking Calendar <= 10.14.11 - missing authorization to sensitive information ex...

CVE ID : CVE-2025-14982 Published : Jan. 16, 2026, 5:16 a.m. | 36 minutes ago Description : The Booking Calendar plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Exposure in all versions up to, and including, 10.14.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view all booking records in the database, including personally identifiable information (PII) such as names, email addresses, phone numbers, physical addresses, payment status, booking costs, and booking hashes belonging to other users. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Jan. 16, 2026
Affected Product: WordPress
Attack Vector: physical