Back

LOW

Bookit < 2.6.0.5 - Bookit Staff+ Arbitrary Appointment Deletion via Missing Authorization

Published Sep 18, 2026

Description

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one of its appointment-deletion functions, allowing users with its low-privileged custom Staff role to delete arbitrary appointments.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner WPScan
Published Sep 18, 2026
Updated Sep 18, 2026
Reserved Sep 10, 2026

CISA Vulnrichment

Updated Sep 18, 2026

NVD

Status Deferred
Modified Sep 18, 2026

Red Hat

No data

ENISA EUVD

Assigner WPScan
Published Sep 18, 2026
Updated Sep 18, 2026

GitHub

No data