Stored XSS Vulnerability in HBook Plugin for WordPress
CVE-2026-8143

7.2HIGH

What is CVE-2026-8143?

The HBook plugin for WordPress is susceptible to Stored Cross-Site Scripting attacks due to inadequate input sanitization and output escaping in the 'hb_country_iso', 'hb_usa_state_iso', and 'hb_canada_province_iso' parameters. This vulnerability affects all versions up to and including 2.1.6, allowing unauthenticated attackers to embed arbitrary malicious web scripts. These scripts will execute on the HBook Customers admin page whenever accessed by users, posing a risk to site integrity and user data security.

Affected Version(s)

Booking Calendar – Event Calendar 0 <= 2.1.6

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hung Nguyen
.