CVE-2026-42751: WordPress Booking Manager plugin <= 2.1.18 - Cross Site Scripting (XSS) vulnerability
Published May 27, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking Manager booking-manager allows Stored XSS.This issue affects Booking Manager: from n/a through <= 2.1.18.
Affected Software
1 affected component
wpdevelop Booking Manager<=2.1.18
Event History
May 27, 2026
CVE Published
via MITRE·09:49 AM
Data Sourced
via MITRE·09:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-42751?
CVE-2026-42751 has a medium severity rating of 6.5.
2
How do I fix CVE-2026-42751?
To fix CVE-2026-42751, upgrade the wpdevelop Booking Manager plugin to a version higher than 2.1.18.
3
What type of vulnerability is CVE-2026-42751?
CVE-2026-42751 is a Cross Site Scripting (XSS) vulnerability.
4
Which WordPress plugin is affected by CVE-2026-42751?
The wpdevelop Booking Manager plugin, versions n/a through 2.1.18, is affected by CVE-2026-42751.
5
What is the impact of CVE-2026-42751?
CVE-2026-42751 allows for Stored XSS, enabling attackers to inject malicious scripts into web pages.