WordPress Plugin Vulnerabilities
Booking Calendar < 11.8 - Unauthenticated Booking Information Disclosure and Modification via Predictable Booking Hash
Description
The plugin does not generate its per-booking access hashes with sufficient entropy, deriving each from a low-entropy time-seeded value, which can allow unauthenticated attackers who are able to determine a booking's creation time to predict the hash and then read that booking's personal data or modify the booking in place.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
INSUFFICIENT CRYPTOGRAPHY
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Olaf Schigt
Submitter
Jasper Weijts (Onvio Pentesting)
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-10-06 (about 2 days ago)
Added
2026-10-06 (about 1 day ago)
Last Updated
2026-10-06 (about 1 day ago)