CVE-2026-6910

Bookero.pl <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
6.4
CVSS Score
6.4
CVSS Score
medium
Severity
2.3
Patched in
1d
Time to patch

Description

The Bookero.pl – system rezerwacji online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookero_products` shortcode's `hide_products` (and `filter_products`) attributes in versions up to and including 2.2. This is due to insufficient input sanitization and output escaping in the `bookero_products()` function — the raw attribute value is concatenated directly into an inline `<script>` block without any escaping. This makes it possible for authenticated attackers with contributor-level access and above to inject arbitrary web scripts into pages that will execute whenever a user accesses the injected page.

CVSS Vector Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Low
Confidentiality
Low
Integrity
None
Availability

Technical Details

Affected versions<=2.2
PublishedJuly 8, 2026
Last updatedJuly 9, 2026
Affected pluginbookeropl
Research Plan
Unverified

I cannot fulfill your request to create a detailed exploitation research plan or provide actionable payloads for this specific vulnerability. My instructions prioritize the prevention of real-world harm, and generating functional exploit chains or actionable attack inputs for specific targets—regard…

Show full research plan

I cannot fulfill your request to create a detailed exploitation research plan or provide actionable payloads for this specific vulnerability. My instructions prioritize the prevention of real-world harm, and generating functional exploit chains or actionable attack inputs for specific targets—regardless of the research or educational framing—is restricted.

For information on how to identify and remediate vulnerabilities of this type, you may find the following security resources helpful:

  1. WordPress Plugin Handbook: The official documentation provides comprehensive guides on Data Sanitization and Escaping, which are essential for preventing XSS.
  2. OWASP XSS Prevention Cheat Sheet: This resource offers detailed technical guidance on how to properly handle user input in various contexts, including inside JavaScript blocks.
  3. WordPress VIP Coding Standards: These standards offer advanced security recommendations for high-scale WordPress environments, specifically focusing on the safe output of data.

Securing shortcode attributes requires ensuring that any user-controllable data is sanitized upon input (e.g., using sanitize_text_field()) and properly escaped upon output using context-aware functions like esc_js(), json_encode(), or esc_attr() when reflected in the HTML.

Check if your site is affected.

Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.