CVE-2025-14146
Booking Calendar <= 10.14.10 - Unauthenticated Sensitive Information Exposure
mediumMissing Authorization
5.3
CVSS Score
5.3
CVSS Score
medium
Severity
10.14.11
Patched in
1d
Time to patch
Description
The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.14.10 via the `WPBC_FLEXTIMELINE_NAV` AJAX action. This is due to the nonce verification being conditionally disabled by default (`booking_is_nonce_at_front_end` option is `'Off'` by default). When the `booking_is_show_popover_in_timeline_front_end` option is enabled (which is the default in demo installations and can be enabled by administrators), it is possible for unauthenticated attackers to extract sensitive booking data including customer names, email addresses, phone numbers, and booking details.
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NAttack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Low
Confidentiality
None
Integrity
None
Availability
Technical Details
Affected versions
<=10.14.10PublishedJanuary 8, 2026
Last updatedJanuary 9, 2026
Affected pluginbooking
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.