The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored reservation data, allowing unauthenticated users to disclose other customers' personal information and booking cancellation tokens.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 10 Oct 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Sat, 10 Oct 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored reservation data, allowing unauthenticated users to disclose other customers' personal information and booking cancellation tokens. | |
| Title | Booking Package < 1.7.30 - Unauthenticated Booking Customer PII Disclosure | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-10T06:00:08.863Z
Reserved: 2026-10-06T11:26:59.919Z
Link: CVE-2026-105995
No data.
Status : Received
Published: 2026-10-10T06:16:40.793
Modified: 2026-10-10T06:16:40.793
Link: CVE-2026-105995
No data.
OpenCVE Enrichment
Updated: 2026-10-10T07:30:14Z
Weaknesses