Sceawere

Vulnerability Detail

CVE-2026-105193UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Booking Calendar Insecure Hash Generation

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.8
Creation Date
8h ago
Vendor
Unknown
Product
Booking Calendar
Attack Type
CWE-326 Inadequate Encryption Strength
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

The Booking Calendar WordPress plugin before 11.8 does not generate its per-booking access hashes with sufficient entropy, deriving each from a low-entropy time-seeded value, which can allow unauthenticated attackers who are able to determine a booking's creation time to predict the hash and then read that booking's personal data or modify the booking in place.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.8",
  "pubDate": "2026-10-08T06:16:39.473Z",
  "pubdate": "2026-10-08T06:16:39.473Z",
  "executiveSummary": "The Booking Calendar WordPress plugin, in versions prior to 11.8, exhibits a critical cryptographic vulnerability due to the implementation of insufficient entropy in the generation of per-booking access hashes.\nThe root cause of this flaw lies in the use of a time-seeded value for generating access tokens, which are intended to secure booking records.\nThis vulnerability allows unauthenticated, remote attackers to predict valid access hashes by correlating the creation time of a booking with the deterministic output of the weak seeding mechanism.\nSuccessful exploitation enables unauthorized access to sensitive personal data associated with specific bookings and allows attackers to perform unauthorized modifications to booking states.\nThe risk profile is high, as the exploitation does not require prior authentication or privileged access, relying only on the attacker's ability to approximate the target booking's creation window.\nOrganizations relying on the affected versions are at significant risk of data exposure and integrity loss, necessitating an immediate upgrade to version 11.8 or later to remediate the insecure PRNG (Pseudo-Random Number Generator) usage.",
  "technicalDetails": "The vulnerability originates from the insecure implementation of the access hash generation function within the Booking Calendar plugin. In affected versions (pre-11.8), the algorithm relies on a low-entropy source based on a time-seeded value to produce the hashes used to authorize access to individual booking resources.\nCryptographically, the weakness stems from the predictability of the time-based seed. Because the seeds are derived from server timestamps that are often discoverable or easily brute-forced via observation of public booking logs, the output of the hash function becomes deterministic. An attacker can reconstruct the state of the random number generator if the approximate creation time of a target booking is known.\nThe attack flow follows a structured sequence: First, the attacker identifies a target booking ID. Second, the attacker obtains the creation timestamp of the target booking, which is often inadvertently leaked through public-facing calendar views, RSS feeds, or HTTP header metadata. Third, the attacker leverages the knowledge of the seeding mechanism to iterate through potential time-based seeds, generating a list of candidate access hashes.\nBy performing automated requests using these candidate hashes, the attacker can verify a match when the server responds with a 200 OK status rather than an authorization error. Once a valid hash is identified, the attacker gains full access to the associated booking entity.\nThe impact of this unauthorized access is two-fold: First, the confidentiality of the booking is compromised, allowing for the exfiltration of personally identifiable information (PII) including names, email addresses, and potential service details. Second, the integrity of the application is undermined, as an attacker with a valid hash can modify booking parameters, such as changing scheduled dates, canceling existing reservations, or injecting malicious booking data, effectively performing an Insecure Direct Object Reference (IDOR) style attack facilitated by broken access control.\nThe attack is performed over the network without requiring any prior authentication, making it a critical threat to any WordPress installation utilizing the affected plugin version. The vulnerable component is the internal hashing logic responsible for managing access tokens for booking entries."
}
CVE-2026-105193: Booking Calendar Insecure Hash Generation (MEDIUM Severity, CVSS: 4.8) | Sceawere