Reflected Cross-Site Scripting Vulnerability in Booking Calendar Plugin by WordPress
CVE-2026-92561
6.1MEDIUM
What is CVE-2026-92561?
The Booking Calendar plugin for WordPress suffers from a Reflected Cross-Site Scripting vulnerability caused by inadequate input sanitization and output escaping in the 'options' parameter. This vulnerability exists in all versions up to and including 11.8.2. Attackers can exploit this flaw to inject malicious scripts into web pages, potentially compromising users who click on crafted links. Furthermore, the plugin’s nonce check is disabled by default, allowing unauthorized requests to bypass security measures and reach the vulnerable code, increasing the risk of exploitation.
Affected Version(s)
Booking Calendar 0 <= 11.8.2