๐Ÿ” CVE Alert

CVE-2026-105193

UNKNOWN 0.0

Booking Calendar < 11.8 - Unauthenticated Booking Information Disclosure and Modification via Predictable Booking Hash

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Booking Calendar WordPress plugin before 11.8 does not generate its per-booking access hashes with sufficient entropy, deriving each from a low-entropy time-seeded value, which can allow unauthenticated attackers who are able to determine a booking's creation time to predict the hash and then read that booking's personal data or modify the booking in place.

Vendor unknown
Product booking calendar
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for unknown booking calendar

Be the first to know when new unknown vulnerabilities affecting unknown booking calendar are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Booking Calendar
0 < 11.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/c6a81cf3-095d-4d7e-83c5-80f44327e7fe/

Credits

Olaf Schigt WPScan