Impact
The Booking Calendar plugin contains a flaw that allows any user with the Editor role or higher to request any WordPress option via one of its settings handlers. By bypassing the expected access restrictions, the plugin returns the full value of the selected option, which can include sensitive core configuration such as database credentials, email settings, or site URLs. An attacker can therefore obtain confidential configuration data that is normally protected by WordPress’s role‑based access control.
Affected Systems
Affected systems are WordPress installations that use the Booking Calendar plugin with a version earlier than 11.8.3. Versions 10.15 through 11.8.2 are vulnerable. The issue is confined to the plugin itself and does not affect the core WordPress software directly. Any site that has enabled the Editor role for one or more users is potentially exposed.
Risk and Exploitability
There is no published CVSS or EPSS score for this vulnerability, and it is not catalogued in CISA’s KEV list. Nonetheless, the flaw is exploitable only by authenticated users who possess Editor or higher privileges, which many sites grant to multiple staff members. Once the attacker can read arbitrary WordPress options, further compromise is possible, especially if the disclosed settings include sensitive credentials or network addresses. The overall risk is moderate to high depending on what data the site exposes and how many users have role privileges.
OpenCVE Enrichment