Vulnerabilities
CVE-2026-1431 - Booking Calendar <= 10.14.13 - missing authorization to unauthenticated booking d...
CVE ID : CVE-2026-1431 Published : Jan. 31, 2026, 5:16 a.m. | 1 hour, 19 minutes ago Description : The Booking Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wpbc_ajax_WPBC_FLEXTIMELINE_NAV() function in all versions up to, and including, 10.14.13. This makes it possible for unauthenticated attackers to retrieve booking information including customer names, phones and emails. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
Affected Product:
WordPress