CVE-2026-12113
Last modified
CVE-2026-12113 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filter_list. This makes it possible for authenticated attackers, with contributor-level access and above, to extract customer names, email addresses, phone numbers, appointment comments, and other booking personally identifiable information.. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filter_list. This makes it possible for authenticated attackers, with contributor-level access and above, to extract customer names, email addresses, phone numbers, appointment comments, and other booking personally identifiable information.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| codepeople | Appointment Booking Calendar | <= 1.4.02 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-12113?
How severe is CVE-2026-12113?
How do I fix CVE-2026-12113?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-12104OS command injection in the environment and tunnel configura…8.6
- CVE-2026-12105Improper access control in Devolutions Server 2026.2.5, 2026…6.5
- CVE-2026-12108The Highlighting Code Block plugin for WordPress is vulnerab…4.4
- CVE-2026-12110The Taskbuilder – Project Management & Task Management Tool …6.5
- CVE-2026-12111The Appointment Booking Calendar plugin for WordPress is vul…4.3
- CVE-2026-12112A flaw was found in the foreman-mcp-server. A session manage…7.8
- CVE-2026-12114The Team Members – Multi Language Supported Team Plugin plug…4.4
- CVE-2026-12115The Counter Box – Add Countdowns, Timers & Dynamic Counters …6.6
- CVE-2026-12116A vulnerability in the Xerte Online Tools allows for RCE thr…9.8
- CVE-2026-12117Improper access control in the social login connection endpo…4.3
- CVE-2026-12118IBM webMethods Integration (on prem) 10.15, 10.11 could allo…9.8
- CVE-2026-12119The Simple File List plugin for WordPress is vulnerable to u…6.5
Are you affected by CVE-2026-12113?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
