CVE-2026-1431

Booking Calendar <= 10.14.13 - Missing Authorization to Unauthenticated Booking Details Exposure

The Booking Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wpbc_ajax_WPBC_FLEXTIMELINE_NAV() function in all versions up to, and including, 10.14.13. This makes it possible for unauthenticated attackers to retrieve booking information including customer names, phones and emails.


We have discovered 11,689 live websites that are affected by CVE-2026-1431.

Run a Free Instant Scan




Affected Software

Product  WP Booking Calendar
Category Wordpress Plugins
Vulnerable Domains11,689 live websites (96% of WP Booking Calendar install base)
Vulnerable Versions
  • from 0 through 10.14.13
Vulnerable Versions Count112 versions ( 99% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jan 31, 2026
  • Updated - Feb 2, 2026

Credits

  • M Indra Purnama (finder)

Website Distribution by Country

Number of websites using CVE-2026-1431
United States2,480 websites



Germany1,477 websites
France1,071 websites
GB660 websites
Italy660 websites
Netherlands605 websites
Spain410 websites
Denmark402 websites
Switzerland309 websites
Czech Republic250 websites

Website Distribution by TLD

Number of websites using CVE-2026-1431
.com4,046 websites
.de942 websites
.fr613 websites
.nl543 websites
.it455 websites
.co.uk436 websites
.org422 websites
.ch269 websites
.se234 websites
.dk226 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-1431

Top websites that are affected by CVE-2026-1431. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.com Curaçao***,***
****.ru Russia***,***
****.org United States***,***
***********.**.uk GB***,***
***.***.pl Poland***,***
**************.ca Canada***,***
*************.de Germany***,***
***********.***.br Brazil***,***
*********.cz Czech Republic***,***
********.com Cyprus***,***
See full domain list

FAQ

CVE-2026-1431 is Missing Authorization in WP Booking Calendar
A total of 11,689 websites have been identified as vulnerable to CVE-2026-1431, based on global website indexing conducted by WebTechSurvey.
The WP Booking Calendar is affected by the CVE-2026-1431 vulnerability.
WP Booking Calendar versions up to and including 10.14.13 are vulnerable to CVE-2026-1431.