CVE-2022-0389: WP Time Slots Booking Form < 1.1.63 - Admin+ Stored Cross-Site Scripting
Published Mar 7, 2022
·Updated
The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed.
Affected Software
1 affected component
CodePeople Wp Time Slots Booking Form Wordpress<1.1.63
Event History
Mar 7, 2022
CVE Published
via MITRE·08:16 AM
Data Sourced
via MITRE·08:16 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-0389?
CVE-2022-0389 is classified as a high severity vulnerability due to its potential for Cross-Site Scripting attacks.
2
How do I fix CVE-2022-0389?
To fix CVE-2022-0389, update the WP Time Slots Booking Form plugin to version 1.1.63 or later.
3
Who is affected by CVE-2022-0389?
CVE-2022-0389 affects installations of the WP Time Slots Booking Form plugin prior to version 1.1.63.
4
What type of attack can CVE-2022-0389 be used for?
CVE-2022-0389 can be exploited for Cross-Site Scripting (XSS) attacks.
5
Can CVE-2022-0389 be exploited by low-privileged users?
No, CVE-2022-0389 requires high privilege users to exploit the vulnerability.