CVE-2026-25435: WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Stored XSS.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.36.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25435?
CVE-2026-25435 has a medium severity rating due to its potential for Cross Site Scripting (XSS) attacks.
How do I fix CVE-2026-25435?
To mitigate CVE-2026-25435, update the wpdevart Booking Calendar plugin to version 3.2.37 or later.
What types of attacks can exploit CVE-2026-25435?
CVE-2026-25435 can be exploited through Cross Site Scripting (XSS) attacks, allowing attackers to inject malicious scripts.
Which versions of wpdevart Booking Calendar are affected by CVE-2026-25435?
CVE-2026-25435 affects wpdevart Booking Calendar versions up to and including 3.2.36.
What is the impact of CVE-2026-25435 on users?
The impact of CVE-2026-25435 includes potential data theft and manipulation of session data due to XSS vulnerabilities.