Description
The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Immediate Upgrade
AI Analysis

Impact

The Booking Calendar plugin contains a flaw that allows any user with the Editor role or higher to request any WordPress option via one of its settings handlers. By bypassing the expected access restrictions, the plugin returns the full value of the selected option, which can include sensitive core configuration such as database credentials, email settings, or site URLs. An attacker can therefore obtain confidential configuration data that is normally protected by WordPress’s role‑based access control.

Affected Systems

Affected systems are WordPress installations that use the Booking Calendar plugin with a version earlier than 11.8.3. Versions 10.15 through 11.8.2 are vulnerable. The issue is confined to the plugin itself and does not affect the core WordPress software directly. Any site that has enabled the Editor role for one or more users is potentially exposed.

Risk and Exploitability

There is no published CVSS or EPSS score for this vulnerability, and it is not catalogued in CISA’s KEV list. Nonetheless, the flaw is exploitable only by authenticated users who possess Editor or higher privileges, which many sites grant to multiple staff members. Once the attacker can read arbitrary WordPress options, further compromise is possible, especially if the disclosed settings include sensitive credentials or network addresses. The overall risk is moderate to high depending on what data the site exposes and how many users have role privileges.

Generated by OpenCVE AI on October 8, 2026 at 07:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Booking Calendar plugin to version 11.8.3 or later, which includes the patch that correctly restricts option visibility.
  • Re‑evaluate the user roles on the site; remove the Editor role from users who do not require it or replace it with a custom role that has limited capability to view plugin settings.
  • Apply an additional role‑and‑capability management plugin and configure it to deny access to the affected settings handlers for all users below administrator level.

Generated by OpenCVE AI on October 8, 2026 at 07:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Thu, 08 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration.
Title Booking Calendar 10.15 - 11.8.2 - Editor+ Arbitrary Option Disclosure
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-08T06:00:06.908Z

Reserved: 2026-10-04T11:56:58.521Z

Link: CVE-2026-105195

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T06:16:40.010

Modified: 2026-10-08T06:16:40.010

Link: CVE-2026-105195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T07:30:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control