Retour à la veille

CVE-2026-14213

Publié : 13 août 2026
Modifié : 13 août 2026
Lien officiel NVD

Description détaillée

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked customer's personal data.

Références et Patchs