CVE-2026-14211EPSS p15.6%

CVE-2026-14211CVE-2026-14211

Description

The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating sequential identifiers.

Scoring

CVSS 3.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
EPSS0.26% probability of exploitation · percentile 15.6% · 2026-10-06T12:00:23Z
Last modified2026-08-26
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.