Ghostwire

CVE-2026-105995: The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored...

MEDIUM CVSS 0.0

Published: October 10, 2026 | Last Modified: October 10, 2026

Description

The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored reservation data, allowing unauthenticated users to disclose other customers' personal information and booking cancellation tokens.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

References