CVE-2023-23971: WordPress WP Time Slots Booking Form Plugin <= 1.1.81 is vulnerable to Cross Site Scripting (XSS)
Published Apr 6, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CodePeople WP Time Slots Booking Form plugin <= 1.1.81 versions.
Affected Software
1 affected component
CodePeople Wp Time Slots Booking Form Wordpress<=1.1.81
Remediation
Information
Update to 1.1.82 or a higher version.
Event History
Apr 6, 2023
CVE Published
via MITRE·05:04 AM
Data Sourced
via MITRE·05:04 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-23971?
CVE-2023-23971 is classified as a high severity vulnerability due to its potential for exploitation through stored Cross-Site Scripting.
2
How do I fix CVE-2023-23971?
To fix CVE-2023-23971, update the CodePeople WP Time Slots Booking Form plugin to the latest version above 1.1.81.
3
Who is affected by CVE-2023-23971?
CVE-2023-23971 affects users of the CodePeople WP Time Slots Booking Form plugin versions 1.1.81 and below.
4
What type of vulnerability is CVE-2023-23971?
CVE-2023-23971 is an authenticated stored Cross-Site Scripting (XSS) vulnerability.
5
Is user authentication required for exploit CVE-2023-23971?
Yes, an authenticated administrator is required to exploit CVE-2023-23971.