A poorly defined global, maybe?
Ok. Thanks for looking into the issue.
Hi there – thanks for looking at this. The issue arose from a Vulnerability scan undertaken by a Plesk install earlier today. I believe the service uses Patchstack ie. https://patchstack.com/database/vulnerability/booking-calendar/wordpress-booking-calendar-plugin-6-2-reflected-cross-site-scripting