First published: Thu Jul 11 2019(Updated: )
The Appointment Hour Booking plugin 1.1.44 for WordPress allows XSS via the E-mail field, as demonstrated by email_1.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CodePeople Appointment Hour Booking | =1.1.44 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Appointment Hour Booking plugin is CVE-2019-13505.
The severity of CVE-2019-13505 is medium, with a severity value of 6.1.
The Appointment Hour Booking plugin vulnerability allows XSS through the E-mail field.
To fix the Appointment Hour Booking plugin vulnerability, update to version 1.1.45 or higher.
You can find more information about the Appointment Hour Booking plugin vulnerability on GitHub, WordPress.org, and WPScan.