Boletines de Vulnerabilidades

CVE-2026-6910

   
Software afectado WORDPRESS
 
The Bookero.pl – system rezerwacji online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookero_products` shortcode's `hide_products` (and `filter_products`) attributes in versions up to and including 2.2. This is due to insufficient input sanitization and output escaping in the `bookero_products()` function — the raw attribute value is concatenated directly into an inline `

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-6910