PatchSiren

Booking Calendar CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Booking Calendar CVE published 2026-10-08

CVE-2026-105195

The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration. This vulnerability allows for potential exposure of sensitive information, emphasizing the need for defend [truncated]

Review Booking Calendar CVE published 2026-10-08

CVE-2026-105193

The Booking Calendar WordPress plugin before 11.8 has a vulnerability allowing unauthenticated attackers to predict booking hashes and access or modify booking information due to low-entropy time-seeded values used in generating these hashes. This vulnerability can lead to unauthorized access to sensitive booking information and potential modification of booking details. Defenders responsible for WordPres [truncated]