{"id":"CVE-2026-14334","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-14334","summary":"The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that…","details":"The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary JavaScript when the SVG is opened, including in the session of an administrator who reviews the submitted booking.","published":"2026-08-19T06:00:15.621Z","modified":"2026-08-19T06:00:15.621Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"EXPLOIT","url":"https://wpscan.com/vulnerability/9ddd1628-0b06-461b-8a5f-ba977f83fa7f/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-19T06:00:15.621Z"}}