CVE-2018-5671: XSS
Published Jan 13, 2018
·Updated
An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php extrafield1[items][fielditem1][pricepercent] parameter.
Affected Software
1 affected component
Booking Calendar Project Booking Calendar Wordpress=2.1.7
Event History
Jan 13, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-5671?
CVE-2018-5671 is classified as a moderate risk vulnerability due to the potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2018-5671?
To fix CVE-2018-5671, update the Booking Calendar plugin to the latest version that addresses this vulnerability.
3
What kind of vulnerability is CVE-2018-5671?
CVE-2018-5671 is identified as a cross-site scripting (XSS) vulnerability.
4
Which versions of the Booking Calendar plugin are affected by CVE-2018-5671?
CVE-2018-5671 specifically affects version 2.1.7 of the Booking Calendar plugin.
5
What impact does CVE-2018-5671 have on WordPress sites?
CVE-2018-5671 can allow attackers to inject malicious scripts into web pages viewed by other users, potentially compromising their data.