๐Ÿ” CVE Alert

CVE-2026-105995

UNKNOWN 0.0

Booking Package < 1.7.30 - Unauthenticated Booking Customer PII Disclosure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored reservation data, allowing unauthenticated users to disclose other customers' personal information and booking cancellation tokens.

Vendor unknown
Product booking package
Published Oct 10, 2026
Stay Ahead of the Next One

Get instant alerts for unknown booking package

Be the first to know when new unknown vulnerabilities affecting unknown booking package are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Booking Package
0 < 1.7.30

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/a778a758-4c44-45d6-bd34-9668bba2a95c/

Credits

Md. Moniruzzaman Prodhan (NomanProdhan) WPScan