First published: Fri Aug 09 2019(Updated: )
The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CodePeople Appointment Hour Booking | =1.3.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14791 has a medium severity rating due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2019-14791, update the Appointment Booking Calendar plugin to a version later than 1.3.18.
CVE-2019-14791 can lead to cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into web pages.
CVE-2019-14791 is considered a common vulnerability for WordPress sites using the affected version of the Appointment Booking Calendar plugin.
CVE-2019-14791 specifically affects version 1.3.18 of the Appointment Booking Calendar plugin for WordPress.