Home

Description

The Booking Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wpbc_ajax_WPBC_FLEXTIMELINE_NAV() function in all versions up to, and including, 10.14.13. This makes it possible for unauthenticated attackers to retrieve booking information including customer names, phones and emails.

PUBLISHED Reserved 2026-01-26 | Published 2026-01-31 | Updated 2026-01-31 | Assigner Wordfence




MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-862 Missing Authorization

Product status

Default status
unaffected

* (semver)
affected

Timeline

2026-01-23:Discovered
2026-01-26:Vendor Notified
2026-01-30:Disclosed

Credits

M Indra Purnama finder

References

www.wordfence.com/...-d9b1-4f6f-ac1a-477950ea2e80?source=cve

plugins.trac.wordpress.org/...0.14.13/core/lib/wpbc-ajax.php

cve.org (CVE-2026-1431)

nvd.nist.gov (CVE-2026-1431)

Download JSON