Stored Cross-Site Scripting in Booking for Appointments and Events Calendar Plugin by WordPress
CVE-2026-10148
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 September 2026
What is CVE-2026-10148?
The Booking for Appointments and Events Calendar plugin for WordPress contains a vulnerability that allows authenticated users with Contributor-level access and above to inject arbitrary scripts into web pages. This weakness stems from inadequate input sanitization and output escaping on the 'load_manually' parameter within the render() methods of various Elementor widgets. Whenever a user accesses the compromised page, their browser executes the malicious scripts, posing a significant security risk. Though a partial patch was introduced in version 2.4.8, users should ensure they are operating on the latest version to mitigate potential exploitation.
Affected Version(s)
Booking for Appointments and Events Calendar β Amelia 0 <= 2.4.9