First published: Mon Oct 16 2023(Updated: )
The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Booking Calendar | <9.7.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4620 is a vulnerability in the Booking Calendar WordPress plugin before version 9.7.3.1 that allows unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators.
The severity of CVE-2023-4620 is medium, with a CVSS score of 6.1.
CVE-2023-4620 affects the Booking Calendar WordPress plugin before version 9.7.3.1 by allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators.
Yes, the fix for CVE-2023-4620 is to update the Booking Calendar WordPress plugin to version 9.7.3.1 or later.
You can find more information about CVE-2023-4620 at the following reference: [CVE-2023-4620](https://wpscan.com/vulnerability/084e9494-2f9e-4420-9bf7-78a1a41433d7).