CVE-2023-29427: WordPress Amelia Plugin <= 1.0.75 is vulnerable to Cross Site Scripting (XSS)
Published Jun 26, 2023
·Updated
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in TMS Booking for Appointments and Events Calendar – Amelia plugin <= 1.0.75 versions.
Affected Software
1 affected component
Tms-outsource Amelia Wordpress<=1.0.75
Remediation
Information
Update to 1.0.76 or a higher version.
Event History
Jun 26, 2023
CVE Published
via MITRE·08:32 AM
Data Sourced
via MITRE·08:32 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-29427?
The severity of CVE-2023-29427 is high.
2
What is the affected software of CVE-2023-29427?
The affected software of CVE-2023-29427 is TMS Booking for Appointments and Events Calendar - Amelia plugin (<= 1.0.75 versions).
3
What is the vulnerability type of CVE-2023-29427?
CVE-2023-29427 is an Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.
4
How can I fix CVE-2023-29427?
To fix CVE-2023-29427, update the TMS Booking for Appointments and Events Calendar - Amelia plugin to a version higher than 1.0.75.
5
What is the CWE category of CVE-2023-29427?
CVE-2023-29427 belongs to CWE category 79 (Cross-Site Scripting).