WordPress Plugin Vulnerabilities

Booking Calendar < 11.8 - Unauthenticated Booking Information Disclosure and Modification via Predictable Booking Hash

Description

The plugin does not generate its per-booking access hashes with sufficient entropy, deriving each from a low-entropy time-seeded value, which can allow unauthenticated attackers who are able to determine a booking's creation time to predict the hash and then read that booking's personal data or modify the booking in place.

Proof of Concept

Affects Plugins

Fixed in 11.8

References

Classification

Type
INSUFFICIENT CRYPTOGRAPHY
CWE

Miscellaneous

Original Researcher
Olaf Schigt
Submitter
Jasper Weijts (Onvio Pentesting)
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-10-06 (about 2 days ago)
Added
2026-10-06 (about 1 day ago)
Last Updated
2026-10-06 (about 1 day ago)

Other