What is CVE-2026-14334?
This vulnerability exists in the 'Booking calendar, Appointment Booking System' WordPress plugin up to version 3.2.36. It allows unauthenticated attackers to bypass the plugin's script-stripping mechanism by uploading specially crafted SVG files, which can lead to cross-site scripting (XSS) attacks. It is recommended to immediately update the plugin to the latest available version.
Azərbaycanca: Bu zəiflik 'Booking calendar, Appointment Booking System' WordPress plaginin 3.2.36-a qədər olan versiyalarında aşkarlanıb. Doğrulanmamış istifadəçilərə xüsusi hazırlanmış SVG faylları yükləməyə imkan verir, çünki plagin skript təmizləmə mexanizmini düzgün tətbiq etmir. Bu, veb-saytda cross-site scripting (XSS) hücumlarına yol aça bilər, ona görə də plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Up to which version is the 'Booking calendar, Appointment Booking System' plugin affected by this vulnerability?
This vulnerability exists in the plugin up to version 3.2.36, so it is recommended to update to the latest available version.
How can unauthenticated attackers exploit this vulnerability?
They can upload specially crafted SVG files due to improper implementation of the script-stripping mechanism, which can lead to cross-site scripting (XSS) attacks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.