Impact
The Booking Calendar plugin for WordPress contains a reflected cross‑site scripting vulnerability that arises from the options parameter. Because the input is not sanitized and output is not escaped, an attacker can craft a URL that injects arbitrary JavaScript into the page shown to a user. When the user clicks the link, the script runs in the victim’s browser, which could be used for phishing, cookie theft, or session hijacking. The vulnerability also bypasses standard nonce protection because the option booking_is_nonce_at_front_end is disabled in the default configuration, allowing unauthenticated requests to reach the vulnerable sink without verification.
Affected Systems
WordPress sites that use the Booking Calendar plugin version 11.8.2 or earlier. The plugin is distributed under the wpdevelop package and the affected portion is identified in the core files across all versions up to 11.8.2.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity exploitation scenario. The EPSS score is below 1 %, suggesting that attacks are currently rare, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw requires only a crafted link and no authentication, a motivated attacker can easily perform small‑scale site compromise or social‑engineering attacks. The primary attack vector is a reflected XSS request triggered by a user clicking a malicious URL and can lead to arbitrary script execution in the victim’s browser.
OpenCVE Enrichment