CVE-2026-105195

Published: Ott 08, 2026 Last Modified: Ott 08, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration.

https://wpscan.com/vulnerability/9d6e9047-410e-4d3d-81f0-e3f89cf7a494/