CVE-2019-14791: XSS
Published Aug 9, 2019
·Updated
The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.
Affected Software
1 affected component
CodePeople Appointment Booking Calendar Wordpress=1.3.18
Event History
Aug 9, 2019
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-14791?
CVE-2019-14791 has a medium severity rating due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2019-14791?
To fix CVE-2019-14791, update the Appointment Booking Calendar plugin to a version later than 1.3.18.
3
What types of attacks can CVE-2019-14791 lead to?
CVE-2019-14791 can lead to cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into web pages.
4
Is CVE-2019-14791 a common vulnerability?
CVE-2019-14791 is considered a common vulnerability for WordPress sites using the affected version of the Appointment Booking Calendar plugin.
5
What versions of the Appointment Booking Calendar are affected by CVE-2019-14791?
CVE-2019-14791 specifically affects version 1.3.18 of the Appointment Booking Calendar plugin for WordPress.