Improperly Sanitized SVG File Upload in Booking Calendar WordPress Plugin
CVE-2026-14334
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 August 2026
Badges
What is CVE-2026-14334?
The Booking Calendar, Appointment Booking System WordPress plugin, up to version 3.2.36, is affected by a vulnerability that fails to adequately sanitize uploaded SVG files. This oversight allows unauthenticated attackers to upload malicious SVG files which can execute arbitrary JavaScript when opened—potentially impacting the sessions of administrators reviewing bookings. By exploiting this vulnerability, attackers can execute harmful scripts within the context of the logged-in admin, leading to unauthorized actions or data exposure.
Affected Version(s)
Booking calendar, Appointment Booking System 3.2.18 <= 3.2.36
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.