PatchSiren

Booking for Appointments and Events Calendar CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Booking for Appointments and Events Calendar CVE published 2026-09-02

CVE-2026-14215

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action chain. This allows an unauthenticated user to trigger booking notifications and integration callbacks for a booking by enumerating its identifier. The affected product is used for managing bookings and events on WordPress sites. The [truncated]

LOW Booking for Appointments and Events Calendar CVE published 2026-08-29

CVE-2026-77704

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were left awaiting approval and overwriting another customer's booking status on a shared appointment.

LOW Booking for Appointments and Events Calendar CVE published 2026-08-10

CVE-2026-14211

The Booking for Appointments and Events Calendar WordPress plugin before version 9.7 has a vulnerability that allows any employee with an Employee Panel login to read and modify customer personal data by enumerating sequential identifiers. This issue affects organizations using the plugin, particularly those with multiple employees accessing customer data. The vulnerability class is related to insufficien [truncated]