Description
The Booking Calendar WordPress plugin before 11.8 does not generate its per-booking access hashes with sufficient entropy, deriving each from a low-entropy time-seeded value, which can allow unauthenticated attackers who are able to determine a booking's creation time to predict the hash and then read that booking's personal data or modify the booking in place.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthenticated booking data disclosure and alteration via predictable booking hash
Action: Patch
AI Analysis

Impact

The Booking Calendar WordPress plugin before version 11.8 generates per‑booking access hashes from a low‑entropy, time‑seeded value. An attacker who can guess or determine a booking’s creation time can predict that booking’s hash, enabling read access to personal data or modification of the booking without authentication. This compromises the confidentiality and integrity of booking information.

Affected Systems

All installations of the Booking Calendar plugin older than 11.8 are vulnerable. The issue is present in every major release prior to 11.8, regardless of other plugin settings or site configuration. Users deploying the Legacy Booking Calendar without an update are at risk.

Risk and Exploitability

The exploit requires only knowledge of a booking’s creation time or a close guess. Since the hash can be computed directly, no additional system access is needed. The EPSS score is unavailable, but the lack of authentication makes this vulnerability highly valuable to attackers. The vulnerability is not in the CISA KEV catalog, yet its impact on user data makes it a priority for remediation.

Generated by OpenCVE AI on October 8, 2026 at 07:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the plugin update to version 11.8 or newer, which eliminates the low‑entropy hash generation method
  • If an update is not immediately possible, restrict external access to the booking URLs by using a firewall or WordPress role‑based restrictions to prevent unauthenticated access
  • After updating, monitor for any unexpected booking changes or access patterns to ensure the fix is effective

Generated by OpenCVE AI on October 8, 2026 at 07:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Booking Calendar WordPress plugin before 11.8 does not generate its per-booking access hashes with sufficient entropy, deriving each from a low-entropy time-seeded value, which can allow unauthenticated attackers who are able to determine a booking's creation time to predict the hash and then read that booking's personal data or modify the booking in place.
Title Booking Calendar < 11.8 - Unauthenticated Booking Information Disclosure and Modification via Predictable Booking Hash
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-08T06:00:06.554Z

Reserved: 2026-10-04T11:54:27.415Z

Link: CVE-2026-105193

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T06:16:39.473

Modified: 2026-10-08T06:16:39.473

Link: CVE-2026-105193

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T08:00:16Z

Weaknesses

No weakness.