Junglewise Threat Intelligence

CVE-2026-59558: wpdevelop Booking Calendar unauthenticated XSS

CVE-2026-59558 · Severity: high · CVSS 7.1 · Published 2026-07-27

Technologies: Wpdevelop Booking Calendar. Vendors: Wpdevelop.

Executive brief

The Booking Calendar plugin for WordPress, which provides online reservation and scheduling functionality, contains a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could potentially hijack user sessions, redirect visitors to malicious websites, or deface the site. This vulnerability can be exploited by remote attackers without needing any login credentials.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Booking Calendar plugin for WordPress (versions <= 11.4.2) due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to execute arbitrary JavaScript in the context of a victim's browser session. Exploitation requires a victim (typically a site administrator) to perform an action, such as clicking a malicious link or visiting a crafted URL. This can lead to session hijacking, unauthorized administrative actions, or the delivery of further browser-based exploits. The issue is resolved in version 11.4.3.

Affected products

  • wpdevelop Booking Calendar <= 11.4.2

Timeline

  • 2026-07-16: disclosed: Reported by researcher daroo to Patchstack
  • 2026-07-27: advisory: Published by Patchstack and NVD
  • 2026-07-27: patched: Fixed in version 11.4.3

References