CVE-2026-105195: vulnerability in Booking Calendar
Booking Calendar 10.15 - 11.8.2 - Editor+ Arbitrary Option Disclosure
Published
0Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Track
exploitation probability
—
observed exploitation
nono source reports it
The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration.
Affected products
Unknown · Booking CalendarRelated CVEs — Booking Calendar
In the same product, most dangerous first.
CVE-2021-25040—Booking Calendar < 8.9.2 - Reflected Cross-Site ScriptingEPSS 0.8%CVE-2023-4620MEDIUMBooking Calendar < 9.7.3.1 - Unauthenticated Stored XSSEPSS 0.6%CVE-2026-105193—Booking Calendar < 11.8 - Unauthenticated Booking Information Disclosure and Modification via Predictable Booking HashEPSS —