Description
The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in all versions up to, and including, 11.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The nonce check is bypassed by default because the 'booking_is_nonce_at_front_end' option ships disabled, allowing unauthenticated requests to reach the vulnerable sink without any verification.
Published: 2026-09-18
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Update Plugin
AI Analysis

Impact

The Booking Calendar plugin for WordPress contains a reflected cross‑site scripting vulnerability that arises from the options parameter. Because the input is not sanitized and output is not escaped, an attacker can craft a URL that injects arbitrary JavaScript into the page shown to a user. When the user clicks the link, the script runs in the victim’s browser, which could be used for phishing, cookie theft, or session hijacking. The vulnerability also bypasses standard nonce protection because the option booking_is_nonce_at_front_end is disabled in the default configuration, allowing unauthenticated requests to reach the vulnerable sink without verification.

Affected Systems

WordPress sites that use the Booking Calendar plugin version 11.8.2 or earlier. The plugin is distributed under the wpdevelop package and the affected portion is identified in the core files across all versions up to 11.8.2.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate severity exploitation scenario. The EPSS score is below 1 %, suggesting that attacks are currently rare, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw requires only a crafted link and no authentication, a motivated attacker can easily perform small‑scale site compromise or social‑engineering attacks. The primary attack vector is a reflected XSS request triggered by a user clicking a malicious URL and can lead to arbitrary script execution in the victim’s browser.

Generated by OpenCVE AI on September 19, 2026 at 20:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Booking Calendar plugin to the latest version, which removes the reflected XSS flaw.
  • If an upgrade cannot be performed immediately, enable the booking_is_nonce_at_front_end option to true so that nonce verification blocks unauthenticated requests to the vulnerable endpoint.
  • Apply a strict Content Security Policy and enable site‑wide XSS filters to reduce the impact of any remaining reflected XSS entry points.

Generated by OpenCVE AI on September 19, 2026 at 20:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpdevelop
Wpdevelop booking Calendar
Vendors & Products Wordpress
Wordpress wordpress
Wpdevelop
Wpdevelop booking Calendar

Fri, 18 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in all versions up to, and including, 11.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The nonce check is bypassed by default because the 'booking_is_nonce_at_front_end' option ships disabled, allowing unauthenticated requests to reach the vulnerable sink without any verification.
Title Booking Calendar <= 11.8.2 - Reflected Cross-Site Scripting via 'options' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Wpdevelop Booking Calendar
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-18T14:31:43.589Z

Reserved: 2026-09-16T13:26:00.340Z

Link: CVE-2026-92561

cve-icon Vulnrichment

Updated: 2026-09-18T14:29:49.328Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T07:16:51.850

Modified: 2026-09-18T15:17:18.230

Link: CVE-2026-92561

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T20:45:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')