CVE-2026-14334
Deferred Deferred - Pending Action

SVG File Upload XSS in Booking Calendar WordPress Plugin

Vulnerability report for CVE-2026-14334, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-26

Assigner: WPScan

Description

The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary JavaScript when the SVG is opened, including in the session of an administrator who reviews the submitted booking.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-26
Generated
2026-09-08
AI Q&A
2026-08-19
EPSS Evaluated
2026-09-07
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
booking_calendar appointment_booking_system to 3.2.36 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Booking calendar, Appointment Booking System WordPress plugin up to version 3.2.36. It allows unauthenticated attackers to upload malicious SVG files that bypass the plugin's sanitization, leading to stored cross-site scripting (XSS). When an administrator reviews the uploaded file, the embedded JavaScript executes, potentially compromising their session.

Detection Guidance

Check for unauthorized SVG uploads in the Booking calendar plugin directory. Review server logs for unexpected JavaScript execution or admin session activity. Inspect WordPress media library for suspicious SVG files.

Impact Analysis

An attacker could upload a malicious SVG file that executes arbitrary JavaScript when opened by an administrator. This could lead to session hijacking, unauthorized actions on the WordPress site, or further compromise of the administrator's system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements or HIPAA's security rules for protected health information. Organizations using this plugin may face compliance breaches if exploited.

Mitigation Strategies

Disable SVG uploads in the Booking calendar plugin. Update to the latest plugin version if available. Implement strict file upload restrictions and scan existing SVG files for malicious content.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14334. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart