PatchSiren

wpdevelop CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH wpdevelop CVE published 2026-07-27

CVE-2026-59558

CVE-2026-59558 is a high-severity Unauthenticated Cross Site Scripting (XSS) vulnerability in Booking Calendar versions up to 11.4.2. The vulnerability has a CVSS score of 7.1 and a CVSS severity of HIGH. This vulnerability could allow attackers to inject malicious scripts into the Booking Calendar, potentially leading to unauthorized actions or data breaches. Users of Booking Calendar versions up to 11.4 [truncated]