Description
The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary JavaScript when the SVG is opened, including in the session of an administrator who reviews the submitted booking.
Published: 2026-08-19
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker can upload a crafted SVG via the Booking calendar, Appointment Booking System plugin that fails to strip embedded scripts. Because the file is stored and rendered, the malicious JavaScript executes immediately when a user—most commonly an administrator—opens or previews the file. The stored XSS allows the attacker to steal credentials, hijack sessions, or perform unauthorized actions within the administrator’s account, compromising site confidentiality and integrity.

Affected Systems

WordPress sites running the Booking calendar, Appointment Booking System plugin version 3.2.36 or earlier are vulnerable. Any deployment of this plugin on a WordPress installation is at risk when unauthenticated users can submit booking requests that include file uploads.

Risk and Exploitability

The flaw carries a CVSS score of 8.8, signifying high severity. Its EPSS score is below 1 %, indicating a low likelihood of widespread exploitation, and it is not listed in CISA KEV. The attack vector is unauthenticated file upload through the plugin’s booking form, with exploitation occurring when a privileged user opens the uploaded SVG. The stored XSS impact is limited to accounts that view the file, but administrators are the most likely target.

Generated by OpenCVE AI on August 20, 2026 at 13:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest release of the Booking calendar, Appointment Booking System plugin (3.2.37 or newer), where SVG uploads are properly sanitized or disabled.
  • If an upgrade is not immediately possible, remove the ability to upload SVG files by editing the plugin’s file‑type restrictions or configuring the WordPress media settings to block SVG.
  • Enable a Web Application Firewall or a security plugin that rejects or sanitizes SVG content before it reaches the Booking calendar plugin.

Generated by OpenCVE AI on August 20, 2026 at 13:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpdevart
Wpdevart booking Calendar, Appointment Booking System
Vendors & Products Wordpress
Wordpress wordpress
Wpdevart
Wpdevart booking Calendar, Appointment Booking System

Wed, 19 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Wed, 19 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary JavaScript when the SVG is opened, including in the session of an administrator who reviews the submitted booking.
Title Booking calendar, Appointment Booking System <= 3.2.36 - Unauthenticated Stored XSS via SVG File Upload
References

Subscriptions

Wordpress Wordpress
Wpdevart Booking Calendar, Appointment Booking System
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-19T16:16:50.277Z

Reserved: 2026-07-01T12:52:36.935Z

Link: CVE-2026-14334

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-19T06:17:33.263

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-14334

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T20:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')