Cross-site Scripting Vulnerability in wpdevart Booking Calendar by WordPress
CVE-2026-25435
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 March 2026
What is CVE-2026-25435?
The wpdevart Booking calendar, Appointment Booking System contains a vulnerability that allows attackers to exploit improper input neutralization during web page generation, leading to Stored Cross-site Scripting (XSS) attacks. This weakness permits malicious users to inject arbitrary scripts, which can be executed in the context of another user's session. Affected versions include those up to and including 3.2.36, making it crucial for users to assess and mitigate potential risks to their installations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Booking calendar, Appointment Booking System <= n/a