Impact
The Booking Calendar WordPress plugin before version 11.8 generates per‑booking access hashes from a low‑entropy, time‑seeded value. An attacker who can guess or determine a booking’s creation time can predict that booking’s hash, enabling read access to personal data or modification of the booking without authentication. This compromises the confidentiality and integrity of booking information.
Affected Systems
All installations of the Booking Calendar plugin older than 11.8 are vulnerable. The issue is present in every major release prior to 11.8, regardless of other plugin settings or site configuration. Users deploying the Legacy Booking Calendar without an update are at risk.
Risk and Exploitability
The exploit requires only knowledge of a booking’s creation time or a close guess. Since the hash can be computed directly, no additional system access is needed. The EPSS score is unavailable, but the lack of authentication makes this vulnerability highly valuable to attackers. The vulnerability is not in the CISA KEV catalog, yet its impact on user data makes it a priority for remediation.
OpenCVE Enrichment