Vulnerabilities / WP Booking System Free version / WPSEC-2026-0653
WP Booking System Free version <= 2.1 - Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header
High 7.2
CWE-79Fixed in 2.1.0.1
- ID
- WPSEC-2026-0653
- Plugin
- WP Booking System – Booking Calendar (wp-booking-system)
- Affected
- from 2.1 before 2.1.0.1
- Remediation
- Update to 2.1.0.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Weakness
- CWE-79
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-08
- Attack surface
- WP Booking System Free version on WPSec AttackSurface
- Fix released
- Published
Description
The WP Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in version 2.1. This is due to insufficient validation of the visitor IP address, which is saved as the booking's customer IP when a public booking form is submitted, and to missing output escaping when that IP address is shown in the admin booking details. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute whenever an administrator, or another user with access to the calendar, opens the affected booking.
References
- https://wpsec.com/vuln/WPSEC-2026-0653/
- https://plugins.svn.wordpress.org/wp-booking-system/tags/2.1.0.1/
- https://wordpress.org/plugins/wp-booking-system/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS