CVE · Medium

CVE-2025-14146 — Booking Calendar [booking] < 10.14.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-14146 Booking Calendar [booking] < 10.14.11 Missing Authorization Medium 5.3 < 10.14.11 10.14.11 2026-01-08

CVE-2025-14146

The Booking Calendar plugin for WordPress contains a vulnerability that allows unauthorized access to sensitive information. This issue affects all versions up to 10.14.10, where the nonce verification is disabled by default in certain circumstances. As a result, attackers can obtain private data such as customer contact information and booking details without authentication.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.