CVE WATCH / VULNERABILITY DETAIL
CVE-2026-105193
MEDIUMCVSS 4.8NVD feed
Published 8 October 2026 · tracked since 8 October 2026
Description
The Booking Calendar WordPress plugin before 11.8 does not generate its per-booking access hashes with sufficient entropy, deriving each from a low-entropy time-seeded value, which can allow unauthenticated attackers who are able to determine a booking's creation time to predict the hash and then re
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-107573 HIGH 7.8
- CVE-2026-107275 MEDIUM 6.8
- CVE-2026-93509 MEDIUM 6.5
- CVE-2026-104660 HIGH 7.8
- CVE-2026-104671 MEDIUM 5.3
- CVE-2026-105190 MEDIUM 5.3
- CVE-2026-103649 HIGH 7.5
- CVE-2026-103010 HIGH 7.8
- CVE-2026-103011 MEDIUM 6.5
- CVE-2026-103517 MEDIUM 5.3