CVE-2022-29443: WordPress Hotel Booking plugin <= 3.0 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark's Hotel Booking plugin <= 3.0 at WordPress.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-29443?
CVE-2022-29443 has a medium severity rating due to the potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2022-29443?
To fix CVE-2022-29443, users should update the Nicdark Hotel Booking plugin to a version higher than 3.0.
Who is affected by CVE-2022-29443?
Users with contributor or higher roles in WordPress installations using Nicdark's Hotel Booking plugin version 3.0 or lower are affected by CVE-2022-29443.
What kind of attacks can result from CVE-2022-29443?
CVE-2022-29443 can lead to authenticated stored XSS attacks, allowing attackers to execute malicious scripts in the context of a user's browser.
Is CVE-2022-29443 under active exploitation?
As of the current information, there is no public indication that CVE-2022-29443 is under active exploitation.