Reflected Cross-Site Scripting Vulnerability in Booking Calendar Plugin by WordPress
CVE-2026-92561

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 September 2026

What is CVE-2026-92561?

The Booking Calendar plugin for WordPress suffers from a Reflected Cross-Site Scripting vulnerability caused by inadequate input sanitization and output escaping in the 'options' parameter. This vulnerability exists in all versions up to and including 11.8.2. Attackers can exploit this flaw to inject malicious scripts into web pages, potentially compromising users who click on crafted links. Furthermore, the plugin’s nonce check is disabled by default, allowing unauthorized requests to bypass security measures and reach the vulnerable code, increasing the risk of exploitation.

Affected Version(s)

Booking Calendar 0 <= 11.8.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuto Hyakumoto
.