CVE-2026-105195

CVE-2026-105195: vulnerability in Booking Calendar

Booking Calendar 10.15 - 11.8.2 - Editor+ Arbitrary Option Disclosure

Published

0Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Track
exploitation probability
—
observed exploitation
nono source reports it
The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration.