CVE-2026-10148 | melograno Booking for Appointments and Events Calendar Plugin Elementor Widget render cross site scripting

SecurityVulns

A vulnerability, which was classified as problematic, was found in melograno Booking for Appointments and Events Calendar Plugin up to 2.4.9 on WordPress. The impacted element is the function render of the component Elementor Widget. The manipulation of the argument load_manually results in cross site scripting.

This vulnerability is identified as CVE-2026-10148. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More