CVE-2023-27918: XSS
Cross-site scripting vulnerability in Appointment and Event Booking Calendar for WordPress - Amelia versions prior to 1.0.76 allows a remote unauthenticated attacker to inject an arbitrary script by having a user who is logging in the WordPress where the product is installed visit a malicious URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27918?
CVE-2023-27918 is classified as a high-severity cross-site scripting vulnerability.
How do I fix CVE-2023-27918?
To fix CVE-2023-27918, update the Appointment and Event Booking Calendar for WordPress - Amelia plugin to version 1.0.76 or later.
Who is affected by CVE-2023-27918?
CVE-2023-27918 affects users of the Appointment and Event Booking Calendar for WordPress - Amelia plugin versions prior to 1.0.76.
What type of attack does CVE-2023-27918 enable?
CVE-2023-27918 enables remote unauthenticated attackers to perform cross-site scripting attacks.
What should I do if I can't update to fix CVE-2023-27918?
If you cannot update, consider disabling the plugin until a safe version can be implemented to mitigate the risk of CVE-2023-27918.