First published: Mon Jun 13 2022(Updated: )
The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
CodePeople Appointment Hour Booking | <1.3.56 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1710 is a vulnerability found in the Appointment Hour Booking WordPress plugin before version 1.3.56.
The severity of CVE-2022-1710 is medium with a CVSS score of 4.8.
CVE-2022-1710 affects the Appointment Hour Booking plugin by allowing high privilege users to perform Cross-Site Scripting attacks.
High privilege users can exploit CVE-2022-1710 by manipulating the Calendar fields in the plugin settings to execute malicious scripts.
Yes, the fix for CVE-2022-1710 is to upgrade to version 1.3.56 or later of the Appointment Hour Booking plugin.