PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-40791 codepeople CVE debrief

CVE-2026-40791 is a HIGH severity Unauthenticated Cross Site Scripting (XSS) vulnerability in WP Time Slots Booking Form versions <= 1.2.46. The vulnerability has a CVSS score of 7.1 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-40791).

Vendor
codepeople
Product
WP Time Slots Booking Form
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-15
Original CVE updated
2026-06-15
Advisory published
2026-06-15
Advisory updated
2026-06-15

Who should care

Users of WP Time Slots Booking Form versions <= 1.2.46 should apply patches or mitigations as available.

Technical summary

The vulnerability is an Unauthenticated Cross Site Scripting (XSS) issue in WP Time Slots Booking Form. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L.

Defensive priority

HIGH

Recommended defensive actions

  • Apply patches or updates for WP Time Slots Booking Form to version > 1.2.46.
  • Review and restrict user input to prevent XSS attacks.

Evidence notes

Evidence from Patchstack indicates a vulnerability in WP Time Slots Booking Form.

Official resources

CVE-2026-40791 was published on 2026-06-15T21:16:51.417Z and modified on 2026-06-15T21:24:32.790Z.