{"id":"CVE-2026-105193","title":"The Booking Calendar WordPress plugin before 11.8 does not generate its per-booking access hashes with sufficient entropy, deriving each from a low-entropy time-seeded value, which can allow unauthenticated attackers who are able to dete…","summary":"The Booking Calendar WordPress plugin before 11.8 does not generate its per-booking access hashes with sufficient entropy, deriving each from a low-entropy time-seeded value, which can allow unauthenticated attackers who are able to dete…","severity":"none","cwe":["CWE-326"],"product":"Booking Calendar","affected":["booking_calendar < 11.8"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T06:16:39.473","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105193","references":[{"url":"https://wpscan.com/vulnerability/c6a81cf3-095d-4d7e-83c5-80f44327e7fe/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-08T07:18:54.837Z","slug":"CVE-2026-105193","body":"## Overview\n\nThe Booking Calendar WordPress plugin before 11.8 does not generate its per-booking access hashes with sufficient entropy, deriving each from a low-entropy time-seeded value, which can allow unauthenticated attackers who are able to determine a booking's creation time to predict the hash and then read that booking's personal data or modify the booking in place.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}