CVE-2026-105995: CWE-200 Information Exposure in Booking Package
Description
The Booking Package WordPress plugin before 1.7.30 does not perform authorization checks before returning stored reservation data, allowing unauthenticated users to disclose other customers' personal information and booking cancellation tokens.
CVSS v3.1
Score 5.3medium
Affected software
Booking Package
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Booking Package WordPress plugin versions prior to 1.7.30 do not perform proper authorization checks when returning stored reservation data. This flaw enables unauthenticated attackers to retrieve sensitive customer information and booking cancellation tokens, resulting in an information exposure vulnerability classified under CWE-200.
Potential Impact
Unauthenticated users can access personal data and booking cancellation tokens of other customers, potentially compromising customer privacy and allowing unauthorized booking cancellations or manipulations.
Mitigation Recommendations
Upgrade the Booking Package plugin to version 1.7.30 or later where this authorization check issue is resolved. Patch status is not explicitly confirmed in the input data, but the affected versions are clearly stated as prior to 1.7.30, indicating that updating to 1.7.30 or newer is the remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-10-06T11:26:59.919Z
- State
- PUBLISHED
Threat ID: 6ac9d5582cdf04f6560b02af
Added to database: 10/10/2026, 06:04:08 UTC
Last enriched: 10/10/2026, 06:18:58 UTC
Last updated: 10/10/2026, 21:26:29 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.