Retour à la veille

CVE-2026-105195

Publié : 8 octobre 2026
Modifié : 8 octobre 2026
Lien officiel NVD

Description détaillée

The Booking Calendar WordPress plugin before 11.8.3 does not adequately restrict which options a lower-privileged user can load through one of its settings handlers, allowing users with the Editor role and above to disclose the values of arbitrary WordPress options, including core site configuration.

Références et Patchs