Unrated severityNVD Advisory· Published Oct 8, 2026
CVE-2026-105195
CVE-2026-105195
Description
The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <11.8.3
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.