CVE-2022-1710: Appointment Hour Booking < 1.3.56 - Admin+ Stored Cross-Site Scripting
The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfilteredhtml is disallowed.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-1710?
CVE-2022-1710 is a vulnerability found in the Appointment Hour Booking WordPress plugin before version 1.3.56.
What is the severity of CVE-2022-1710?
The severity of CVE-2022-1710 is medium with a CVSS score of 4.8.
How does CVE-2022-1710 affect the Appointment Hour Booking plugin?
CVE-2022-1710 affects the Appointment Hour Booking plugin by allowing high privilege users to perform Cross-Site Scripting attacks.
How can high privilege users exploit CVE-2022-1710?
High privilege users can exploit CVE-2022-1710 by manipulating the Calendar fields in the plugin settings to execute malicious scripts.
Is there a fix for CVE-2022-1710?
Yes, the fix for CVE-2022-1710 is to upgrade to version 1.3.56 or later of the Appointment Hour Booking plugin.