PT-2026-107834 · WordPress · Booking Calendar

·

CVE-2026-105195

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Booking Calendar WordPress plugin versions prior to 11.8.3
Description An issue exists where a settings handler does not adequately restrict the options that lower-privileged users can load. This allows users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration.
Recommendations Update Booking Calendar WordPress plugin to version 11.8.3 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105195

Affected Products

Booking Calendar