Vulnerability in Booking Calendar — CVE-2026-105195
LowSeverity
0.2%Estimated exploit probability
50,000+ sitesInstalls
11.8.3Fixed in
What to do now
Update Booking Calendar to 11.8.3 or later.
Affected versions
- 10.15 to 11.8.2 (inclusive)
Affected: Booking Calendar (plugin, booking)
What the vulnerability is
The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 10.15 through 11.8.2. This makes it possible for authenticated attackers, with editor-level access and above, to extract sensitive user or configuration data.