CVE-2026-14216
MEDIUM 6.5EPSS 0.4%
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.
- CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L - EPSS
- 0.41% chance of exploitation in the next 30 days, 34th percentile
- Published
- 2026-08-26