PatchSiren

Booking for Appointments and Events Calendar CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Booking for Appointments and Events Calendar CVE published 2026-08-10

CVE-2026-14211

The Booking for Appointments and Events Calendar WordPress plugin before version 9.7 has a vulnerability that allows any employee with an Employee Panel login to read and modify customer personal data by enumerating sequential identifiers. This issue affects organizations using the plugin, particularly those with multiple employees accessing customer data. The vulnerability class is related to insufficien [truncated]