---
id: CVE-2026-93655
title: >-
  The Booking Calendar plugin for WordPress is vulnerable to Reflected
  Cross-Site Scripting via the 'wpbc_auto_fill' parameter in all versions up to,
  and including, 11.8.3 due to insufficient input sanitization and output
  escaping
summary: >-
  The Booking Calendar plugin for WordPress is vulnerable to Reflected
  Cross-Site Scripting via the 'wpbc_auto_fill' parameter in all versions up to,
  and including, 11.8.3 due to insufficient input sanitization and output
  escaping. This ma…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: wpdevelop
product: Booking Calendar
affected:
  - booking_calendar <= 11.8.3
published: '2026-09-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:04:55.677'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93655'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/booking/tags/11.8.3/_dist/all/_src/wpbc_all.js#L3370
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/booking/tags/11.8.3/_dist/all/_src/wpbc_all.js#L3396
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/booking/tags/11.8.3/js/wpbc_time-selector.js#L87
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3703002%40booking&new=3703002%40booking
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/37fdbbc3-6151-4962-90fa-a621d01a5eb2?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-22T12:43:02.009381Z'
ingestedAt: '2026-09-22T05:59:04.885Z'
epss: 0.00368
epssPercentile: 0.27889
---

## Overview

The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill' parameter in all versions up to, and including, 11.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
