CVE-2026-12111
Last modified
CVE-2026-12111 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.4.01. This is due to insufficient authorization and missing per-calendar ownership checks in the cpabc_appointments_calendar_load2() function, which is reachable via the cpabc_calendar_load2=1 query parameter in wp-admin and only checks is_admin() && current_user_can('edit_posts'), a capability available to Contributor-level users and above. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.4.01. This is due to insufficient authorization and missing per-calendar ownership checks in the cpabc_appointments_calendar_load2() function, which is reachable via the cpabc_calendar_load2=1 query parameter in wp-admin and only checks is_admin() && current_user_can('edit_posts'), a capability available to Contributor-level users and above. This makes it possible for authenticated attackers with Contributor-level access and above to supply an arbitrary calendar ID via the id parameter and extract customer booking information, including email addresses, names, phone numbers, booking times, and comments, from any calendar managed by the plugin.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-12111?
How severe is CVE-2026-12111?
How do I fix CVE-2026-12111?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-12102The UsersWP – Front-end login form, User Registration, User …2.7
- CVE-2026-12103The Wallet for WooCommerce plugin for WordPress is vulnerabl…4.3
- CVE-2026-12104OS command injection in the environment and tunnel configura…8.6
- CVE-2026-12105Improper access control in Devolutions Server 2026.2.5, 2026…6.5
- CVE-2026-12108The Highlighting Code Block plugin for WordPress is vulnerab…4.4
- CVE-2026-12110The Taskbuilder – Project Management & Task Management Tool …6.5
- CVE-2026-12112A flaw was found in the foreman-mcp-server. A session manage…7.8
- CVE-2026-12113The Appointment Booking Calendar plugin for WordPress is vul…4.3
- CVE-2026-12114The Team Members – Multi Language Supported Team Plugin plug…4.4
- CVE-2026-12115The Counter Box – Add Countdowns, Timers & Dynamic Counters …6.6
- CVE-2026-12116A vulnerability in the Xerte Online Tools allows for RCE thr…9.8
- CVE-2026-12117Improper access control in the social login connection endpo…4.3
Are you affected by CVE-2026-12111?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
