CVE-2026-105995
Booking Package < 1.7.30 - Unauthenticated Booking Customer PII Disclosure
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored reservation data, allowing unauthenticated users to disclose other customers' personal information and booking cancellation tokens.
| Vendor | unknown |
| Product | booking package |
| Published | Oct 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown booking package
Be the first to know when new unknown vulnerabilities affecting unknown booking package are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Booking Package
0 < 1.7.30
References
Credits
Md. Moniruzzaman Prodhan (NomanProdhan) WPScan