CVE-2026-105995: Unknown Booking Package

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored reservation data, allowing unauthenticated users to disclose other customers' personal information and booking cancellation tokens.

Affected products

  • Unknown Booking Package: before 1.7.30 (fixed in 1.7.30)

Published 2026-10-10. Last modified 2026-10-10.