PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105195 Booking Calendar CVE debrief

The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration. This vulnerability allows for potential exposure of sensitive information, emphasizing the need for defenders to verify exposure and restrict Editor role privileges promptly. The CVE Program record and NVD vulnerability detail provide official information on the vulnerability, while a supplemental source reference from WPScan offers additional technical details.

Vendor
Booking Calendar
Product
Booking Calendar
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders managing WordPress installations with the Booking Calendar plugin should verify exposure and restrict Editor role privileges to prevent disclosure of arbitrary WordPress option values, potentially exposing core site configuration. This involves reviewing the current installation and ensuring that appropriate measures are taken to secure the plugin and prevent unauthorized access to sensitive information.

Why it matters

Defenders should prioritize verifying exposure of Booking Calendar versions 10.15 to 11.8.2 and restrict Editor role privileges to prevent disclosure of arbitrary WordPress option values, potentially exposing core site configuration.

  • Disclosure of arbitrary WordPress option values
  • Potential exposure of core site configuration

Technical summary

The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration. This vulnerability can lead to the exposure of sensitive information, emphasizing the need for defenders to verify exposure and restrict Editor role privileges promptly. The technical details indicate a need for immediate action to prevent potential disclosure of core site configuration.

Defensive priority

Defenders should prioritize verifying exposure of Booking Calendar versions 10.15 to 11.8.2 and restrict Editor role privileges.

Recommended defensive actions

  • Verify Booking Calendar version and restrict Editor role privileges
  • Review WordPress option access controls
  • Monitor for suspicious option access
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE Program record and NVD vulnerability detail provide official information on the vulnerability. A supplemental source reference from WPScan offers additional technical details. Defenders should verify the exposure of Booking Calendar versions 10.15 to 11.8.2 and restrict Editor role privileges to prevent disclosure of arbitrary WordPress option values. This involves reviewing WordPress option access controls and monitoring for suspicious option access. The information provided by these sources helps in understanding the scope,

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105195 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105195

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105195 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105195

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.