GHSA-2c7f-rp38-5cq9LowCVSS 2.7

The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a...

Published
October 8, 2026
Last Modified
October 8, 2026

🔗 CVE IDs covered (1)

📋 Description

The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration.

🔗 References (3)