CVE-2026-105995 PUBLISHED

Booking Package < 1.7.30 - Unauthenticated Booking Customer PII Disclosure

Assigner: WPScan
Reserved: 06.10.2026 Published: 10.10.2026 Updated: 10.10.2026

The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored reservation data, allowing unauthenticated users to disclose other customers' personal information and booking cancellation tokens.

Product Status

Vendor Unknown
Product Booking Package
Versions Default: unaffected
  • affected from 0 to 1.7.30 (excl.)

Credits

  • Md. Moniruzzaman Prodhan (NomanProdhan) finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE