CVE-2026-105195
Booking Calendar 10.15 - 11.8.2 - Editor+ Arbitrary Option Disclosure
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration.
| Vendor | unknown |
| Product | booking calendar |
| Published | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown booking calendar
Be the first to know when new unknown vulnerabilities affecting unknown booking calendar are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Booking Calendar
10.15 < 11.8.3
References
Credits
vuxvinh WPScan