WordPress · Booking Calendar · CVE-2026-14334
**Name of the Vulnerable Software and Affected Versions**
Booking calendar, Appointment Booking System WordPress plugin versions prior to 3.2.37
**Description**
The plugin fails to properly sanitize uploaded SVG files. This allows unauthenticated attackers to upload a file that bypasses the script-stripping mechanism and executes arbitrary JavaScript when the SVG is opened, which can occur during an administrator's review of a submitted booking.
**Recommendations**
Update the Booking calendar, Appointment Booking System WordPress plugin to version 3.2.37 or later.