# Booking Package <= 1.7.29 - Unauthenticated Sensitive Information Exposure via 'public' Parameter

- **ID:** WPSEC-2026-0575
- **Plugin:** Booking Package (`booking-package`), https://wordpress.org/plugins/booking-package/
- **Affected versions:** all versions before 1.7.30
- **Fixed in:** 1.7.30 (Update to 1.7.30 or later.)
- **Severity:** High 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **Weakness:** CWE-200
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/booking-package
- **Fix released:** 2026-10-05
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0575/

## Description

The Booking Package plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.29. This is due to the front-end booking request handler deciding whether to return the public or the administrative view of the booking calendar from a user-supplied 'public' parameter, which defaulted to the administrative view when omitted. This makes it possible for unauthenticated attackers to retrieve other customers' booking records for any calendar and month, including the personal details entered in the booking form (such as names, email addresses and phone numbers) and the tokens used to view and cancel bookings.

## References

- https://wpsec.com/vuln/WPSEC-2026-0575/
- https://plugins.svn.wordpress.org/booking-package/tags/1.7.30/
- https://wordpress.org/plugins/booking-package/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0575/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
