{
 "id": "WPSEC-2026-0575",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0575/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0575/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0575/index.md",
 "title": "Booking Package <= 1.7.29 - Unauthenticated Sensitive Information Exposure via 'public' Parameter",
 "description": "The Booking Package plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.29. This is due to the front-end booking request handler deciding whether to return the public or the administrative view of the booking calendar from a user-supplied 'public' parameter, which defaulted to the administrative view when omitted. This makes it possible for unauthenticated attackers to retrieve other customers' booking records for any calendar and month, including the personal details entered in the booking form (such as names, email addresses and phone numbers) and the tokens used to view and cancel bookings.",
 "plugin": {
  "slug": "booking-package",
  "name": "Booking Package",
  "full_name": "Booking Package",
  "wordpress_org": "https://wordpress.org/plugins/booking-package/",
  "advisories_url": "https://wpsec.com/vuln/plugin/booking-package/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/booking-package"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-200"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 7.5,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "1.7.30",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 1.7.30"
  ]
 },
 "introduced_in": null,
 "fixed_in": "1.7.30",
 "remediation": "Update to 1.7.30 or later.",
 "fix_released": "2026-10-05T03:42:32+00:00",
 "published": "2026-10-07T16:47:54+00:00",
 "updated": "2026-10-07T16:15:09.841093+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0575/",
  "https://plugins.svn.wordpress.org/booking-package/tags/1.7.30/",
  "https://wordpress.org/plugins/booking-package/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/booking-package",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "None seen",
  "as_of": "2026-10-07"
 }
}