CVE-2026-14211EPSS p3.2%

CVE-2026-14211CVE-2026-14211

Description

The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating sequential identifiers.

Scoring

CVSS 3.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
EPSS0.13% probability of exploitation · percentile 3.2% · 2026-08-11T12:00:17Z
Last modified2026-08-11
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.