← Vulnerability feed

Vulnerability record · CVE-2021-25040 · published 3 January 2022

CVE-2021-25040: Booking calendar project booking calendar cross-site scripting vulnerability

Booking Calendar Project · Booking Calendar

The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

6.1 CVSS 3.1 Medium EPSS 0.80% · top 45.2% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
0.80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-25040 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-1463Booking calendar project booking calendar deserialization of untrusted data vulnerabilityThe Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and includ…EPSS 1.7%8.8CVE-2018-20556Booking calendar project booking calendar sql injection vulnerabilitySQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_…EPSS 19%8.8CVE-2018-5673Booking calendar project booking calendar cross-site request forgery vulnerabilityAn issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php.EPSS 0.77%6.1CVE-2023-36384Booking calendar project booking calendar cross-site scripting vulnerabilityUnauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodePeople Booking Calendar Contact Form plugin <= 1.2.40 versions.EPSS 0.41%6.1CVE-2017-2151Booking calendar project booking calendar cross-site scripting vulnerabilityCross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via uns…EPSS 0.85%5.3CVE-2017-2150Booking calendar project booking calendar path traversal vulnerabilityDirectory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted c…EPSS 2.4%4.8CVE-2018-5671Booking calendar project booking calendar cross-site scripting vulnerabilityAn issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php extra_field1[items][field_item1][pr…EPSS 0.62%4.8CVE-2018-5672Booking calendar project booking calendar cross-site scripting vulnerabilityAn issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php form_field5[label] parameter.EPSS 0.62%

Source: NIST National Vulnerability Database (record CVE-2021-25040), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.