PatchSiren

Booking Package CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Booking Package CVE published 2026-10-10

CVE-2026-105995

The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored reservation data, allowing unauthenticated users to disclose other customers' personal information and booking cancellation tokens. This vulnerability affects WordPress installations with the Booking Package plugin, potentially leading to unauthorized access to sensitive customer data. Defender [truncated]