---
id: CVE-2026-105995
title: >-
  The Booking Package WordPress plugin before 1.7.30 does not perform
  authorization checks before returning stored reservation data, allowing
  unauthenticated users to disclose other customers' personal information and
  booking cancellation …
summary: >-
  The Booking Package WordPress plugin before 1.7.30 does not perform
  authorization checks before returning stored reservation data, allowing
  unauthenticated users to disclose other customers' personal information and
  booking cancellation …
severity: none
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T06:16:40.793'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105995'
references:
  - url: 'https://wpscan.com/vulnerability/a778a758-4c44-45d6-bd34-9668bba2a95c/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-10-10T06:24:42.864Z'
---

## Overview

The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored reservation data, allowing unauthenticated users to disclose other customers' personal information and booking cancellation tokens.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
