CVE-2026-105193

CVE-2026-105193 published: The Booking Calendar WordPress plugin before 11.8 does not generate its per-booking access hashes with sufficient entropy, deriving each from a low-entropy time-seeded value, which can allow unauthenticated attackers who are able to determine a booking's cr...

View full NVD advisory → ← Back to CVE watch