Executive brief
The Booking Calendar plugin for WordPress, widely used to manage appointment and room reservations on websites, contains a reflected cross-site scripting vulnerability in the 'wpbc_auto_fill' parameter. An attacker can craft a malicious link that, when clicked by a user, injects arbitrary JavaScript code into the page, potentially stealing session cookies, credentials, or redirecting users to phishing sites. This requires social engineering to trick a user into clicking a link but does not require the attacker to be authenticated.
Technical details
Reflected XSS vulnerability in the Booking Calendar WordPress plugin due to insufficient input sanitization and output escaping on the 'wpbc_auto_fill' parameter. An unauthenticated attacker can craft a malicious URL containing JavaScript payload that executes in the victim's browser when the link is visited. The vulnerability requires user interaction (clicking a link) and affects all versions up to and including 11.8.3.
Affected products
- Booking Calendar Booking Calendar up to and including 11.8.3
Timeline
- 2026-09-22: disclosed