First published: Tue Jul 18 2023(Updated: )
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodePeople Booking Calendar Contact Form plugin <= 1.2.40 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Booking Calendar | <=1.2.40 |
Update to 1.2.41 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-36384 is considered a medium severity vulnerability due to the potential for unauthenticated reflected cross-site scripting (XSS) attacks.
To fix CVE-2023-36384, update the CodePeople Booking Calendar Contact Form plugin to version 1.2.41 or later.
CVE-2023-36384 allows attackers to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking or data theft.
Any WordPress sites using the CodePeople Booking Calendar Contact Form plugin version 1.2.40 or earlier are affected by CVE-2023-36384.
Yes, CVE-2023-36384 is relatively easy to exploit as it involves crafting a malicious URL that triggers the reflected XSS in the vulnerable plugin.