First published: Wed Aug 21 2019(Updated: )
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CodePeople Booking Calendar Contact Form | <1.0.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-10908 is classified as medium due to its potential for Cross-Site Scripting (XSS) attacks.
To fix CVE-2016-10908, update the booking-calendar-contact-form plugin to version 1.0.24 or later.
CVE-2016-10908 is a Cross-Site Scripting (XSS) vulnerability affecting the booking-calendar-contact-form plugin.
Versions of the booking-calendar-contact-form plugin prior to 1.0.24 are affected by CVE-2016-10908.
CVE-2016-10908 is found in the booking-calendar-contact-form plugin for WordPress.