CVE-2026-14216
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
26/08/2026
Last modified:
26/08/2026
Description
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM



