CVE-2015-7320: XSS
Multiple cross-site scripting (XSS) vulnerabilities in cpabcappointmentsadminintbookingslist.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7320?
CVE-2015-7320 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2015-7320?
To fix CVE-2015-7320, upgrade the Appointment Booking Calendar plugin to version 1.1.8 or higher.
What are the potential impacts of CVE-2015-7320?
The potential impacts of CVE-2015-7320 include arbitrary web script or HTML injection that could compromise user data.
Which versions of the Appointment Booking Calendar are affected by CVE-2015-7320?
Versions prior to 1.1.8 of the Appointment Booking Calendar plugin are affected by CVE-2015-7320.
Who can exploit CVE-2015-7320?
Remote attackers can exploit CVE-2015-7320 through unspecified vectors to perform cross-site scripting attacks.