Junglewise Threat Intelligence

CVE-2025-13968: Starboard Suite Reservation Calendars Stored XSS in shortcode

CVE-2025-13968 · Severity: medium · CVSS 6.4 · Published 2026-07-11

Executive brief

The Starboard Suite Reservation Calendars plugin for WordPress, which is used to display booking calendars on websites, contains a security flaw. An attacker with basic contributor-level access can inject malicious scripts into website pages. These scripts will automatically run in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.

Technical details

The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the [starboard-suite-lightbox] shortcode attributes. This vulnerability allows authenticated attackers with Contributor-level permissions or higher to inject arbitrary web scripts into pages. The injected scripts are stored and will execute in the context of any user's browser session when they visit the compromised page. The issue affects all versions up to and including 3.1.4. A patch has been released in subsequent versions to address the sanitization failure.

Affected products

  • starboardsuite Starboard Suite Reservation Calendars up to, and including, 3.1.4

Timeline

  • 2026-07-11: advisory: NVD publication date

References