CVE-2026-105195: Unknown Booking Calendar

Low severity, CVSS 2.7. EPSS: 0.2% chance of exploitation in the next 30 days.

The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration.

Affected products

  • Unknown Booking Calendar: from 10.15, before 11.8.3 (fixed in 11.8.3)

Published 2026-10-08. Last modified 2026-10-08.