WordPress Plugin Vulnerabilities

Bookero.pl < 2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

Description

The Bookero.pl – system rezerwacji online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookero_products` shortcode's `hide_products` (and `filter_products`) attributes in versions up to and including 2.2. This is due to insufficient input sanitization and output escaping in the `bookero_products()` function — the raw attribute value is concatenated directly into an inline `<script>` block without any escaping. This makes it possible for authenticated attackers with contributor-level access and above to inject arbitrary web scripts into pages that will execute whenever a user accesses the injected page.

Affects Plugins

Fixed in 2.3

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
zaim
Verified
No

Timeline

Publicly Published
2026-07-08 (about 2 months ago)
Added
2026-07-08 (about 2 months ago)
Last Updated
2026-07-09 (about 2 months ago)

Other