CVE-2026-14334 PUBLISHED

Booking calendar, Appointment Booking System <= 3.2.36 - Unauthenticated Stored XSS via SVG File Upload

Assigner: WPScan
Reserved: 01.07.2026 Published: 19.08.2026 Updated: 19.08.2026

The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary JavaScript when the SVG is opened, including in the session of an administrator who reviews the submitted booking.

Product Status

Vendor Unknown
Product Booking calendar, Appointment Booking System
Versions Default: unknown
  • affected from 3.2.18 to 3.2.36 (incl.)

Credits

  • Samdup Choephel finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE