A vulnerability was found in codepeople Appointment Booking Calendar Plugin up to 1.4.01 on WordPress and classified as problematic . The affected element is the function cpabc_appointments_calendar_load2 of the component Query Parameter Handler . The manipulation of the argument ID results in information disclosure. This vulnerability is known as CVE-2026-12111 . It is possible to launch the attack remotely. No exploit is available.