Sceawere

Vulnerability Detail

CVE-2026-105995UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Booking Package Unauthenticated Data Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
8h ago
Vendor
Unknown
Product
Booking Package
Attack Type
CWE-200 Information Exposure
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored reservation data, allowing unauthenticated users to disclose other customers' personal information and booking cancellation tokens.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-10T06:16:40.793Z",
  "pubdate": "2026-10-10T06:16:40.793Z",
  "executiveSummary": "The Booking Package WordPress plugin, in versions prior to 1.7.30, contains an authorization flaw resulting in an Insecure Direct Object Reference (IDOR) vulnerability.\nThe vulnerability allows unauthenticated, remote attackers to retrieve sensitive customer information and booking cancellation tokens stored within the system.\nThe lack of access control checks on endpoints responsible for fetching reservation data enables the unauthorized disclosure of PII (Personally Identifiable Information).\nThe vulnerability poses a high risk to data privacy and account integrity, as the exposure of cancellation tokens permits attackers to potentially disrupt or manipulate reservation states without legitimate authorization.\nSuccessful exploitation requires no prior authentication or administrative privileges, making it accessible to any external actor with network access to the affected WordPress installation.",
  "technicalDetails": "The vulnerability resides in the Booking Package plugin's handling of reservation data retrieval requests. The root cause is the absence of server-side authorization checks within the functions responsible for processing requests for stored booking records.\nIn a secure implementation, the application should verify the identity and permissions of the user requesting information, ensuring the requester is either an administrator or the legitimate owner of the reservation.\nIn the affected versions, the plugin fails to implement these checks, allowing any user who can reach the API or specific backend endpoint to query the database for reservation details simply by guessing or iterating over reservation identifiers.\nThe attack flow proceeds as follows: 1) The attacker identifies the endpoint responsible for fetching booking details or reservation summaries. 2) The attacker sends an HTTP request to this endpoint without providing valid authentication tokens or session cookies. 3) Because the plugin code lacks capability checks (e.g., current_user_can()) before executing the query, the server processes the request and retrieves the stored data from the database. 4) The server serializes the reservation record, which includes customer names, contact details, and the unique booking cancellation token, and returns this data in the HTTP response body.\nThe impact is significant due to the exposure of cancellation tokens, which are sensitive identifiers intended only for the customer. With these tokens, an attacker can facilitate unauthorized service cancellations, leading to business disruption and loss of trust.\nFurthermore, the exposure of PII constitutes a breach of data privacy compliance requirements. The vulnerability affects all versions of the Booking Package plugin prior to 1.7.30, and exploitation is possible over any network where the WordPress site is reachable, requiring no elevated privileges or complex payload obfuscation, as the vulnerability exists at the logic level within the plugin's data access layer."
}
CVE-2026-105995: Booking Package Unauthenticated Data Disclosure (MEDIUM Severity, CVSS: 5.3) | Sceawere