{"id":"CVE-2026-105195","title":"The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of…","summary":"The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of…","severity":"none","cwe":["CWE-200"],"product":"Booking Calendar","affected":["booking_calendar >= 10.15 < 11.8.3"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T06:16:40.010","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105195","references":[{"url":"https://wpscan.com/vulnerability/9d6e9047-410e-4d3d-81f0-e3f89cf7a494/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-08T07:18:54.838Z","slug":"CVE-2026-105195","body":"## Overview\n\nThe Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}