CVE-2023-4620: Booking Calendar < 9.7.3.1 - Unauthenticated Stored XSS
The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-4620?
CVE-2023-4620 is a vulnerability in the Booking Calendar WordPress plugin before version 9.7.3.1 that allows unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators.
What is the severity of CVE-2023-4620?
The severity of CVE-2023-4620 is medium, with a CVSS score of 6.1.
How does CVE-2023-4620 affect the Booking Calendar plugin?
CVE-2023-4620 affects the Booking Calendar WordPress plugin before version 9.7.3.1 by allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators.
Is there a fix for CVE-2023-4620?
Yes, the fix for CVE-2023-4620 is to update the Booking Calendar WordPress plugin to version 9.7.3.1 or later.
Where can I find more information about CVE-2023-4620?
You can find more information about CVE-2023-4620 at the following reference: [CVE-2023-4620](https://wpscan.com/vulnerability/084e9494-2f9e-4420-9bf7-78a1a41433d7).