PT-2026-107834 · WordPress · Booking Calendar
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Booking Calendar WordPress plugin versions prior to 11.8.3
Description
An issue exists where a settings handler does not adequately restrict the options that lower-privileged users can load. This allows users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration.
Recommendations
Update Booking Calendar WordPress plugin to version 11.8.3 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Booking Calendar