CVE-2023-36384: WordPress Booking Calendar Contact Form Plugin <= 1.2.40 is vulnerable to Cross Site Scripting (XSS)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodePeople Booking Calendar Contact Form plugin <= 1.2.40 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Booking Calendar Contact Form Plugin (CodePeople)to a version that resolves this vulnerability.Fixed in 1.2.41
Event History
Frequently Asked Questions
What is the severity of CVE-2023-36384?
CVE-2023-36384 is considered a medium severity vulnerability due to the potential for unauthenticated reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2023-36384?
To fix CVE-2023-36384, update the CodePeople Booking Calendar Contact Form plugin to version 1.2.41 or later.
What is the impact of CVE-2023-36384?
CVE-2023-36384 allows attackers to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking or data theft.
Who is affected by CVE-2023-36384?
Any WordPress sites using the CodePeople Booking Calendar Contact Form plugin version 1.2.40 or earlier are affected by CVE-2023-36384.
Is CVE-2023-36384 easy to exploit?
Yes, CVE-2023-36384 is relatively easy to exploit as it involves crafting a malicious URL that triggers the reflected XSS in the vulnerable plugin.