What is CVE-2026-14211?
This vulnerability exists in the 'Booking for Appointments and Events Calendar' WordPress plugin before version 9.7. Any authenticated employee can read and modify the stored personal data of any customer, even without any association to that customer. Updating the plugin to the latest version is recommended.
Azərbaycanca: Bu boşluq WordPress üçün 'Booking for Appointments and Events Calendar' pluginində aşkarlanıb. 9.7 versiyasından əvvəlki versiyalar təsirlənir: autentifikasiya olunmuş hər hansı bir işçi (provider) öz müştərisi olmasa belə, istənilən müştərinin şəxsi məlumatlarını oxuya və dəyişdirə bilir. Pluginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which WordPress plugin is affected by CVE-2026-14211?
This vulnerability affects the 'Booking for Appointments and Events Calendar' plugin in versions prior to 9.7.
What can an authenticated employee do by exploiting CVE-2026-14211?
Any authenticated employee (provider) can read and modify the stored personal data of any customer, even without any association to that customer.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.