Executive brief
The Bookit WordPress plugin for managing bookings and appointments failed to properly check user permissions on a feature that retrieves appointment data. This allows staff members with low-privilege roles to view sensitive customer information—including names, email addresses, phone numbers, and private booking notes—from other users' appointments, exposing customer privacy.
Technical details
The vulnerability is an authorization bypass (CWE-200: Exposure of Sensitive Information) in the appointment-retrieval functionality of the Bookit plugin versions before 2.6.0.5. The vulnerable component fails to perform proper access control checks on an appointment action, allowing a user with a low-privilege plugin-specific role to access appointment records they should not be able to view. Attack requires an authenticated account with a staff or similar low-privilege role in the plugin. An attacker can enumerate and read arbitrary appointment records to harvest customer PII including names, emails, phone numbers, and private comments. The vulnerability is fixed in version 2.6.0.5 and later.
Affected products
- Bookit Bookit — Booking & Appointment Calendar before 2.6.0.5
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: fixed in version 2.6.0.5