PatchSiren cyber security CVE debrief
CVE-2026-105995 Booking Package CVE debrief
The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored reservation data, allowing unauthenticated users to disclose other customers' personal information and booking cancellation tokens. This vulnerability affects WordPress installations with the Booking Package plugin, potentially leading to unauthorized access to sensitive customer data. Defenders should assess exposure and prioritize upgrading to version 1.7.30 or later. The CVE record and source item provide limited information about the vulnerability, but indicate that unauthenticated users can disclose other customers' personal information and booking cancellation
- Vendor
- Booking Package
- Product
- Booking Package
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for WordPress installations with the Booking Package plugin should assess exposure and prioritize upgrading to version 1.7.30 or later.
Why it matters
CVE-2026-105995 allows unauthenticated users to disclose other customers' personal information and booking cancellation tokens. Defenders should prioritize verifying exposure and upgrading to version 1.7.30 or later.
- Potential disclosure of customer personal information
- Potential disclosure of booking cancellation tokens
- Verification of Booking Package installations for exposure
- Prioritization of upgrades to version 1.7.30 or later
Technical summary
The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored reservation data, allowing unauthenticated users to access sensitive customer information. This vulnerability is related to the plugin's handling of reservation data and highlights the importance of proper authorization checks in WordPress plugins. Affected installations should be upgraded to version 1.7.30 or later to mitigate this vulnerability.
Defensive priority
Defenders should prioritize verifying exposure of Booking Package installations and upgrading to version 1.7.30 or later.
Recommended defensive actions
- Verify Booking Package installations for exposure
- Upgrade to version 1.7.30 or later
- Monitor for unauthorized access to reservation data
Evidence notes
The CVE record and source item provide limited information about the vulnerability, but indicate that unauthenticated users can disclose other customers' personal information and booking cancellation tokens.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105995 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105995
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105995 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105995
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Booking Package < 1.7.30 - Unauthenticated Booking Customer PII Disclosure
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105995.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/a778a758-4c44-45d6-bd34-9668bba2a95c/
Supplemental source - exploit, vdb-entry, technical-description
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.