First published: Mon Oct 04 2021(Updated: )
The Appointment Hour Booking WordPress plugin before 1.3.16 does not escape some of the Calendar Form settings, allowing high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
CodePeople Appointment Hour Booking | <1.3.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-24673.
The title of this vulnerability is 'The Appointment Hour Booking WordPress plugin before 1.3.16 does not escape some of the Calendar Form settings'.
The severity of CVE-2021-24673 is medium with a severity value of 4.8.
The Appointment Hour Booking WordPress plugin before version 1.3.16 is affected by CVE-2021-24673.
This vulnerability can be exploited by high privilege users to perform Stored Cross-Site Scripting attacks.