Vulnerability Description
The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary JavaScript when the SVG is opened, including in the session of an administrator who reviews the submitted booking.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-14334?
CVE-2026-14334 is a vulnerability with a CVSS score of 8.8 (HIGH). The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Bo...
How severe is CVE-2026-14334?
CVE-2026-14334 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-14334?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.