WP Booking System Free version <= 2.1 - Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header

High 7.2 CWE-79Fixed in 2.1.0.1
ID
WPSEC-2026-0653
Plugin
WP Booking System – Booking Calendar (wp-booking-system)
Affected
from 2.1 before 2.1.0.1
Remediation
Update to 2.1.0.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-08
Attack surface
WP Booking System Free version on WPSec AttackSurface
Fix released
Published

Description

The WP Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in version 2.1. This is due to insufficient validation of the visitor IP address, which is saved as the booking's customer IP when a public booking form is submitted, and to missing output escaping when that IP address is shown in the admin booking details. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute whenever an administrator, or another user with access to the calendar, opens the affected booking.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0