CVE-2026-105995
Received Received - Intake

Unauthenticated Information Disclosure in Booking Package WordPress Plugin

Vulnerability report for CVE-2026-105995, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: WPScan

Description

The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored reservation data, allowing unauthenticated users to disclose other customers' personal information and booking cancellation tokens.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Booking Package 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Booking Package WordPress plugin before version 1.7.30 has a vulnerability where it does not check if users are authorized before showing stored reservation data. This allows unauthenticated users to access other customers' personal information and booking cancellation tokens.

Detection Guidance

Check if your Booking Package WordPress plugin version is below 1.7.30. You can do this by logging into your WordPress admin panel, navigating to Plugins, and reviewing the version of the Booking Package plugin.

Impact Analysis

Unauthenticated users can view other customers' personal data and booking details, leading to privacy breaches and potential misuse of cancellation tokens. This could result in identity theft, fraud, or unauthorized changes to bookings.

Compliance Impact

This vulnerability likely violates GDPR due to unauthorized access to personal data and HIPAA if health-related booking data is exposed. Organizations may face fines, legal penalties, and reputational damage for failing to protect sensitive customer information.

Mitigation Strategies

Immediately update the Booking Package plugin to version 1.7.30 or later to fix the authorization check issue. If you cannot update immediately, consider disabling the plugin until you can apply the patch.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105995. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart