Sceawere

Vulnerability Detail

CVE-2026-105195UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Booking Calendar Arbitrary Option Disclosure

Vulnerability Metadata

Severity
Low
Score / CVSS
2.7
Creation Date
8h ago
Vendor
Unknown
Product
Booking Calendar
Attack Type
CWE-200 Information Exposure
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "2.7",
  "pubDate": "2026-10-08T06:16:40.010Z",
  "pubdate": "2026-10-08T06:16:40.010Z",
  "executiveSummary": "The Booking Calendar WordPress plugin, in versions prior to 11.8.3, is susceptible to an arbitrary option disclosure vulnerability stemming from insufficient access control within its settings handler functionality.\nThis vulnerability is categorized as an improper access control issue, allowing authenticated users with the Editor role or higher to bypass intended restrictions.\nBy manipulating requests handled by the plugin, an attacker can retrieve the values of arbitrary WordPress options stored in the 'wp_options' table. This includes critical core site configuration data, potentially encompassing sensitive information such as API keys, mail server credentials, site URLs, and other configuration settings essential to the integrity and confidentiality of the WordPress installation.\nThe vulnerability requires the attacker to possess at least Editor-level privileges, limiting the initial attack surface to authenticated users, though it remains a significant risk for environments where internal user trust is assumed.\nExploitation allows for the unauthorized extraction of sensitive data which may facilitate further attacks, including privilege escalation or full system compromise, depending on the nature of the information stored within the WordPress database.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper validation and authorization checks performed by the Booking Calendar plugin's settings retrieval handler. The affected component does not implement adequate input sanitization or restricted allow-lists for the 'option_name' parameter passed to internal functions responsible for fetching WordPress site options.\nTypically, WordPress options are managed via the 'get_option()' function. If a plugin's handler accepts user-supplied input to dictate which option to retrieve without validating that the requested option is within an authorized scope, it allows an attacker to query any entry within the 'wp_options' table.\nThe attack flow proceeds as follows: An attacker authenticated with at least the Editor role identifies the endpoint or AJAX/REST API action used by the plugin to fetch settings. By intercepting or constructing a request to this handler, the attacker injects an arbitrary option key into the request parameter that the plugin uses to call the underlying data retrieval function.\nBecause the plugin fails to restrict this parameter, the application executes a database query for the requested, unauthorized option name. The resulting value is then returned to the user in the HTTP response. This allows for the iterative enumeration of the entire 'wp_options' database table.\nThe impact is significant, as the 'wp_options' table often contains sensitive environmental configurations. An attacker can disclose credentials, private site URLs, or plugin-specific settings that may reveal further attack vectors. This vulnerability exists in all versions of the Booking Calendar plugin prior to 11.8.3. The exposure is confined to the server-side, requiring the attacker to have an active, authenticated session with the WordPress administrative interface as a user with sufficient permissions to invoke the plugin's settings handlers."
}
CVE-2026-105195: Booking Calendar Arbitrary Option Disclosure (LOW Severity, CVSS: 2.7) | Sceawere