GHSA-2c7f-rp38-5cq9LowCVSS 2.7
The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a...
🔗 CVE IDs covered (1)
📋 Description
The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration.