The Course Booking System WordPress plugin before 7.0.9 does not restrict access to its booking export, allowing unauthenticated users to download the name, email address and billing address of every customer who has booked a course.
CVE-2026-96886
NONE
Updated Sep 30, 2026
WordPress
CVE Details
CVE ID
CVE-2026-96886
Published Date
Sep 30, 2026
Vendor
WordPress
Severity
NONE
Impact
Minimal impact
Source
View Advisory