Vulnerabilities / Booking Package / WPSEC-2026-0575

Booking Package <= 1.7.29 - Unauthenticated Sensitive Information Exposure via 'public' Parameter

High 7.5 CWE-200Fixed in 1.7.30
ID
WPSEC-2026-0575
Plugin
Booking Package (booking-package)
Affected
all versions before 1.7.30
Remediation
Update to 1.7.30 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness
CWE-200
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
Attack surface
Booking Package on WPSec AttackSurface
Fix released
Published

Description

The Booking Package plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.29. This is due to the front-end booking request handler deciding whether to return the public or the administrative view of the booking calendar from a user-supplied 'public' parameter, which defaulted to the administrative view when omitted. This makes it possible for unauthenticated attackers to retrieve other customers' booking records for any calendar and month, including the personal details entered in the booking form (such as names, email addresses and phone numbers) and the tokens used to view and cancel bookings.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0