CVE-2026-6910
|
| |
|
|
Software afectado |
WORDPRESS |
|
|
|
The Bookero.pl – system rezerwacji online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookero_products` shortcode's `hide_products` (and `filter_products`) attributes in versions up to and including 2.2. This is due to insufficient input sanitization and output escaping in the `bookero_products()` function — the raw attribute value is concatenated directly into an inline ` |
Link: |
| https://nvd.nist.gov/vuln/detail/CVE-2026-6910 |