PoC Index

CVE-2026-14216

MEDIUM 6.5EPSS 0.4%

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.

CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
EPSS
0.41% chance of exploitation in the next 30 days, 34th percentile
Published
2026-08-26

Proof-of-concept exploits (1)

References

Related