CVE-2026-105193
Received Received - Intake

Insufficient Entropy in Booking Hashes in WordPress Booking Calendar

Vulnerability report for CVE-2026-105193, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: WPScan

Description

The Booking Calendar WordPress plugin before 11.8 does not generate its per-booking access hashes with sufficient entropy, deriving each from a low-entropy time-seeded value, which can allow unauthenticated attackers who are able to determine a booking's creation time to predict the hash and then read that booking's personal data or modify the booking in place.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Booking Calendar 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Booking Calendar WordPress plugin before version 11.8 generates weak access hashes for bookings using low-entropy, time-seeded values. This makes the hashes predictable, allowing unauthenticated attackers to guess them if they know when a booking was created. Attackers can then access or modify personal booking data without authentication.

Detection Guidance

Check the installed version of the Booking Calendar WordPress plugin. If it is below 11.8, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files directly.

Impact Analysis

If you use the vulnerable Booking Calendar plugin, attackers could read or alter your booking data, including personal information. This could lead to privacy breaches, unauthorized changes to reservations, or exposure of sensitive details like names, contact info, or booking specifics.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA due to unauthorized access to personal data. GDPR requires protecting personal data, and HIPAA mandates safeguarding health-related information. A breach could result in legal penalties, fines, or reputational damage.

Mitigation Strategies

Update the Booking Calendar plugin to version 11.8 or later immediately. Disable the plugin temporarily if an update is not immediately available. Monitor for unauthorized access or modifications to bookings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105193. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart