Starboard Suite Reservation Calendars
Starboard Suite Reservation Calendars has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Starboard Suite Reservation Calendars has a vendor fix available, so running the current release closes it.
All of these findings were reported by Gilang - DJ. Starboard Suite Reservation Calendars is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-13968Starboard Suite Reservation Calendars <= 3.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
Read the full analysisVulnerability Records

Starboard Suite Reservation Calendars
Author
Starboard Suite
Embed booking calendars easily using shortcodes. Learn more about the Starboard Suite reservation system at starboardsuite.com. Includes shortcodes for embedded calendars ([starboard-suite-embedded]) and buttons that open a booking lightbox ([starboard-suite-lightbox]). For more examples and available options, please visit https://support.starboardsuite.com/en/articles/2334214-using-our-wordpress-plugin. Shortcode options [starboard-suite-lightbox]Book Now[/starboard-suite-lightbox] Accepted attributes: tour_type_id – open to a specific Event Type or parent Event Type departure_location_id – open to a specific Departure Location or parent Departure Location vessel_id – open to a specific Resource width – lightbox width (default 100%) height – lightbox height (default 100%) max-height – lightbox max height max-width – lightbox max width (default 1290px) border-size – border size (default 10px) border-color – border color (default white) hide-giftcertificate – hide Buy Gift Certificates icon (default false) hide-concierge – hide concierge login link (default false) show-printpass – show print icon on boarding pass (default false) notify-printpass-navigateaway – show alert before closing if pass has not been printed (default false) [starboard-suite-embedded] Accepted attributes: tour_type_id – filter to a specific Event Type or parent Event Type departure_location_id – filter to a specific Departure Location or parent Departure Location width – embedded calendar width (default 100%) height – embedded calendar height (default 600px) max-height – embedded calendar max height max-width – embedded calendar max width border – embedded calendar border value (example: 3px solid red) Only the attributes above are supported.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C