CVE-2026-105193: CWE-326 Inadequate Encryption Strength in Booking Calendar
Description
The Booking Calendar WordPress plugin before 11.8 does not generate its per-booking access hashes with sufficient entropy, deriving each from a low-entropy time-seeded value, which can allow unauthenticated attackers who are able to determine a booking's creation time to predict the hash and then read that booking's personal data or modify the booking in place.
CVSS v3.1
Score 4.8medium
Affected software
Booking Calendar
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-105193 describes a vulnerability in the Booking Calendar WordPress plugin prior to version 11.8. The plugin generates per-booking access hashes with inadequate entropy, relying on a time-seeded value with low randomness. An attacker who can determine the booking creation time may predict the access hash, thereby gaining unauthorized access to personal booking information or the ability to alter bookings.
Potential Impact
Unauthenticated attackers who can estimate the creation time of a booking can predict the access hash, potentially exposing personal data associated with that booking or allowing modification of the booking details. This compromises confidentiality and integrity of booking data.
Mitigation Recommendations
Upgrade the Booking Calendar plugin to version 11.8 or later, where this issue has been addressed by improving the entropy used in generating access hashes. No other mitigation is indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-10-04T11:54:27.415Z
- State
- PUBLISHED
Threat ID: 6ac735da2cdf04f656f03ea1
Added to database: 10/08/2026, 06:19:06 UTC
Last enriched: 10/08/2026, 06:34:14 UTC
Last updated: 10/09/2026, 05:48:07 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.