WordPress Plugin Vulnerabilities

Booking Calendar 10.15 - 11.8.2 - Editor+ Arbitrary Option Disclosure

Description

The plugin does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration.

Proof of Concept

Affects Plugins

Fixed in 11.8.3

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE
CVSS

Miscellaneous

Original Researcher
vuxvinh
Submitter
vuxvinh
Verified
Yes

Timeline

Publicly Published
2026-10-06 (about 2 days ago)
Added
2026-10-06 (about 1 day ago)
Last Updated
2026-10-06 (about 1 day ago)

Other