# WP Booking System Free version <= 2.1 - Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header

- **ID:** WPSEC-2026-0653
- **Plugin:** WP Booking System – Booking Calendar (`wp-booking-system`), https://wordpress.org/plugins/wp-booking-system/
- **Affected versions:** from 2.1 before 2.1.0.1
- **Fixed in:** 2.1.0.1 (Update to 2.1.0.1 or later.)
- **Severity:** High 7.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-79
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wp-booking-system
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0653/

## Description

The WP Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in version 2.1. This is due to insufficient validation of the visitor IP address, which is saved as the booking's customer IP when a public booking form is submitted, and to missing output escaping when that IP address is shown in the admin booking details. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute whenever an administrator, or another user with access to the calendar, opens the affected booking.

## References

- https://wpsec.com/vuln/WPSEC-2026-0653/
- https://plugins.svn.wordpress.org/wp-booking-system/tags/2.1.0.1/
- https://wordpress.org/plugins/wp-booking-system/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0653/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
