CVE-2026-25435 | wpdevart Booking calendar, Appointment Booking System booking-calendar Plugin cross site scripting
A vulnerability classified as problematic has been found in wpdevart Booking calendar, Appointment Booking System booking-calendar Plugin up to 3.2.36 on WordPress. The affected element is an unknown function. This manipulation causes cross site scripting.
The identification of this vulnerability is CVE-2026-25435. It is possible to initiate the attack remotely. There is no exploit available.