Sceawere

Vulnerability Detail

CVE-2026-18496UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Booking Calendar Sensitive Data Exposure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
2h ago
Vendor
wpdevelop
Product
Booking Calendar
Attack Type
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.4.3 via the wpbc_is_show_popover_in_flex_timeline() function. This makes it possible for unauthenticated attackers to extract sensitive data including names, email addresses, and phone numbers of customers who have made bookings.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-10T06:16:42.543Z",
  "pubdate": "2026-10-10T06:16:42.543Z",
  "executiveSummary": "The Booking Calendar plugin for WordPress contains a critical Sensitive Information Exposure vulnerability affecting all versions up to and including 11.4.3.\nThe vulnerability stems from improper access control within the wpbc_is_show_popover_in_flex_timeline() function, which exposes private booking details to unauthorized parties.\nUnauthenticated attackers can leverage this flaw to programmatically extract personally identifiable information (PII), including customer names, email addresses, and phone numbers.\nThe risk implication is significant as the exposure of booking metadata facilitates potential phishing campaigns, identity theft, and severe violations of data privacy regulations such as GDPR.\nExploitation requires no special authentication, allowing any remote, unauthenticated attacker to query the vulnerable endpoint and harvest customer data residing within the plugin's database tables.\nImmediate remediation is necessary to prevent continued unauthorized access to sensitive user data.",
  "technicalDetails": "The vulnerability is localized within the plugin's core booking management logic, specifically centered on the function wpbc_is_show_popover_in_flex_timeline().\nThis function is designed to handle the rendering of dynamic popover elements within the flex timeline interface; however, it fails to implement adequate authorization checks or capability verification before returning sensitive booking data to the requester.\nIn versions 11.4.3 and earlier, the function provides an insecure pathway where internal booking objects are fetched and serialized for client-side consumption without validating the session state of the user initiating the request.\nThe attack flow begins when an unauthenticated attacker sends a specifically crafted HTTP request targeting the plugin's frontend or AJAX interface that invokes the vulnerable function. Because the function lacks conditional logic to verify the user's role (e.g., administrator or booking manager), the server-side process executes a query against the booking database.\nUpon successful execution, the function returns a JSON-encoded response or an HTML snippet containing sensitive metadata. This metadata includes PII such as full names, email addresses, and phone numbers associated with existing customer bookings.\nThe root cause is an insecure direct object reference or missing function-level access control, allowing an unauthenticated principal to interface with a privileged administrative data retrieval method. Because the function is reachable via standard web requests, the exposure is accessible over any public network where the WordPress instance is hosted.\nThe post-exploitation impact allows for automated scraping of customer booking records. An attacker could potentially iterate through valid booking IDs to extract bulk datasets of user information. Given that this function does not require any nonce validation or session tokens, the attack is trivial to automate and difficult to detect through standard logging, as the request appears as a legitimate interaction with the calendar interface.\nThe vulnerability remains present because the plugin assumes that the frontend timeline is only accessible to authorized users, failing to account for direct function calls or manipulation of the request parameters that force the execution of the data-fetching logic."
}
CVE-2026-18496: Booking Calendar Sensitive Data Exposure (MEDIUM Severity, CVSS: 5.3) | Sceawere