CVE-2019-13505: XSS
Published Jul 11, 2019
·Updated
The Appointment Hour Booking plugin 1.1.44 for WordPress allows XSS via the E-mail field, as demonstrated by email1.
Affected Software
1 affected component
Dwbooster Appointment Hour Booking Wordpress=1.1.44
Event History
Jul 11, 2019
CVE Published
via MITRE·12:26 PM
Data Sourced
via MITRE·12:26 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for the Appointment Hour Booking plugin?
The vulnerability ID for the Appointment Hour Booking plugin is CVE-2019-13505.
2
What is the severity of CVE-2019-13505?
The severity of CVE-2019-13505 is medium, with a severity value of 6.1.
3
How does the Appointment Hour Booking plugin vulnerability allow XSS?
The Appointment Hour Booking plugin vulnerability allows XSS through the E-mail field.
4
How can I fix the Appointment Hour Booking plugin vulnerability?
To fix the Appointment Hour Booking plugin vulnerability, update to version 1.1.45 or higher.
5
Where can I get more information about the Appointment Hour Booking plugin vulnerability?
You can find more information about the Appointment Hour Booking plugin vulnerability on GitHub, WordPress.org, and WPScan.