CVE-2026-105195
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Oct 08, 2026
Vendor
unknown
Description
The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration.