CVE-2023-35048: WordPress Booking and Rental Manager Plugin <= 1.2.1 is vulnerable to Cross Site Scripting (XSS)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Booking and Rental Manager for Bike plugin <= 1.2.1 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MagePeople Team Booking and Rental Manager for Bike (WordPress plugin)to a version that resolves this vulnerability.Fixed in 1.2.2
Event History
Frequently Asked Questions
What is the severity of CVE-2023-35048?
CVE-2023-35048 is classified as a medium severity vulnerability due to its potential for exploitation in web applications.
How do I fix CVE-2023-35048?
To fix CVE-2023-35048, it is recommended to update the MagePeople Team Booking and Rental Manager for Bike plugin to version 1.2.2 or later.
What kind of vulnerability is CVE-2023-35048?
CVE-2023-35048 is an authenticated stored cross-site scripting (XSS) vulnerability.
Which versions of the software are affected by CVE-2023-35048?
CVE-2023-35048 affects versions of the MagePeople Team Booking and Rental Manager plugin up to and including 1.2.1.
Who is affected by CVE-2023-35048?
Users of the MagePeople Team Booking and Rental Manager for Bike plugin who have version 1.2.1 or earlier installed are affected by CVE-2023-35048.