The Booking Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wpbc_ajax_WPBC_FLEXTIMELINE_NAV() function in all versions up to, and including, 10.14.13. This makes it possible for unauthenticated attackers to retrieve booking information including customer names, phones and emails.
We have discovered 11,689 live websites that are affected by CVE-2026-1431.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 11,689 live websites (96% of WP Booking Calendar install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 112 versions ( 99% of all versions) |
| 2,480 websites | |
| 1,477 websites | |
| 1,071 websites | |
| 660 websites | |
| 660 websites | |
| 605 websites | |
| 410 websites | |
| 402 websites | |
| 309 websites | |
| 250 websites |
| .com | 4,046 websites |
| .de | 942 websites |
| .fr | 613 websites |
| .nl | 543 websites |
| .it | 455 websites |
| .co.uk | 436 websites |
| .org | 422 websites |
| .ch | 269 websites |
| .se | 234 websites |
| .dk | 226 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.com | ***,*** | ||
| ****.ru | ***,*** | ||
| ****.org | ***,*** | ||
| ***********.**.uk | ***,*** | ||
| ***.***.pl | ***,*** | ||
| **************.ca | ***,*** | ||
| *************.de | ***,*** | ||
| ***********.***.br | ***,*** | ||
| *********.cz | ***,*** | ||
| ********.com | ***,*** |
FAQ