{
 "id": "WPSEC-2026-0653",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0653/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0653/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0653/index.md",
 "title": "WP Booking System Free version <= 2.1 - Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header",
 "description": "The WP Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in version 2.1. This is due to insufficient validation of the visitor IP address, which is saved as the booking's customer IP when a public booking form is submitted, and to missing output escaping when that IP address is shown in the admin booking details. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute whenever an administrator, or another user with access to the calendar, opens the affected booking.",
 "plugin": {
  "slug": "wp-booking-system",
  "name": "WP Booking System Free version",
  "full_name": "WP Booking System – Booking Calendar",
  "wordpress_org": "https://wordpress.org/plugins/wp-booking-system/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wp-booking-system/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wp-booking-system"
 },
 "type": "XSS",
 "cwe": [
  "CWE-79"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 7.2,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": "2.1",
    "from_inclusive": true,
    "to": "2.1.0.1",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 2.1 before 2.1.0.1"
  ]
 },
 "introduced_in": "2.1",
 "fixed_in": "2.1.0.1",
 "remediation": "Update to 2.1.0.1 or later.",
 "fix_released": "2026-10-07T12:59:33+00:00",
 "published": "2026-10-08T13:48:37+00:00",
 "updated": "2026-10-07T15:30:51.092091+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0653/",
  "https://plugins.svn.wordpress.org/wp-booking-system/tags/2.1.0.1/",
  "https://wordpress.org/plugins/wp-booking-system/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wp-booking-system",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "None seen",
  "as_of": "2026-10-08"
 }
}