Stored XSS Vulnerability in HBook Plugin for WordPress
CVE-2026-8143
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 May 2026
What is CVE-2026-8143?
The HBook plugin for WordPress is susceptible to Stored Cross-Site Scripting attacks due to inadequate input sanitization and output escaping in the 'hb_country_iso', 'hb_usa_state_iso', and 'hb_canada_province_iso' parameters. This vulnerability affects all versions up to and including 2.1.6, allowing unauthenticated attackers to embed arbitrary malicious web scripts. These scripts will execute on the HBook Customers admin page whenever accessed by users, posing a risk to site integrity and user data security.
Affected Version(s)
Booking Calendar β Event Calendar 0 <= 2.1.6