First published: Mon Jan 03 2022(Updated: )
The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Booking Calendar | <8.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25040 has a medium severity level due to the potential for reflected cross-site scripting exploits.
To fix CVE-2021-25040, update the Booking Calendar plugin to version 8.9.2 or later.
CVE-2021-25040 allows for reflected cross-site scripting attacks that could lead to user data theft or session hijacking.
CVE-2021-25040 affects all versions of the Booking Calendar plugin prior to 8.9.2.
Yes, CVE-2021-25040 is a vulnerability specifically related to the Booking Calendar plugin for WordPress.