CVE-2022-0709: Saasproject Booking Package

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response to unauthenticated users performing a booking, leading to a sensitive data disclosure vulnerability.

Affected products

  • Saasproject Booking Package: before 1.5.29 (fixed in 1.5.29)

Published 2022-04-04. Last modified 2026-06-17.