Impact
An unauthenticated attacker can upload a crafted SVG via the Booking calendar, Appointment Booking System plugin that fails to strip embedded scripts. Because the file is stored and rendered, the malicious JavaScript executes immediately when a user—most commonly an administrator—opens or previews the file. The stored XSS allows the attacker to steal credentials, hijack sessions, or perform unauthorized actions within the administrator’s account, compromising site confidentiality and integrity.
Affected Systems
WordPress sites running the Booking calendar, Appointment Booking System plugin version 3.2.36 or earlier are vulnerable. Any deployment of this plugin on a WordPress installation is at risk when unauthenticated users can submit booking requests that include file uploads.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, signifying high severity. Its EPSS score is below 1 %, indicating a low likelihood of widespread exploitation, and it is not listed in CISA KEV. The attack vector is unauthenticated file upload through the plugin’s booking form, with exploitation occurring when a privileged user opens the uploaded SVG. The stored XSS impact is limited to accounts that view the file, but administrators are the most likely target.
OpenCVE Enrichment