CVE-2026-105195: Booking Calendar 10.15 - 11.8.2 - Editor+ Arbitrary Option Disclosure
The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Booking Calendar WordPress pluginto a version that resolves this vulnerability.Fixed in 11.8.3