Improperly Sanitized SVG File Upload in Booking Calendar WordPress Plugin
CVE-2026-14334

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 August 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-14334?

The Booking Calendar, Appointment Booking System WordPress plugin, up to version 3.2.36, is affected by a vulnerability that fails to adequately sanitize uploaded SVG files. This oversight allows unauthenticated attackers to upload malicious SVG files which can execute arbitrary JavaScript when opened—potentially impacting the sessions of administrators reviewing bookings. By exploiting this vulnerability, attackers can execute harmful scripts within the context of the logged-in admin, leading to unauthorized actions or data exposure.

Affected Version(s)

Booking calendar, Appointment Booking System 3.2.18 <= 3.2.36

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Samdup Choephel
WPScan
.