The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple REST API endpoints in all versions up to, and including, 1.0.16. This makes it possible for unauthenticated attackers to query sensitive data.
Metrics
Affected Vendors & Products
References
History
Tue, 10 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arraytics
Arraytics booktics – Booking Calendar For Appointments And Service Businesses Wordpress Wordpress wordpress |
|
| Vendors & Products |
Arraytics
Arraytics booktics – Booking Calendar For Appointments And Service Businesses Wordpress Wordpress wordpress |
Tue, 10 Mar 2026 02:45:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-03-10T02:21:49.636Z
Updated: 2026-03-10T02:21:49.636Z
Reserved: 2026-02-04T16:38:59.005Z
Link: CVE-2026-1919
No data.
No data.
No data.