CVE-2023-50860: WordPress Amelia Plugin <= 1.0.85 is vulnerable to Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TMS Booking for Appointments and Events Calendar – Amelia allows Stored XSS.This issue affects Booking for Appointments and Events Calendar – Amelia: from n/a through 1.0.85.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50860?
CVE-2023-50860 has been classified as a high-severity vulnerability due to its potential for exploitation via stored cross-site scripting (XSS).
How do I fix CVE-2023-50860?
To fix CVE-2023-50860, update the Booking for Appointments and Events Calendar – Amelia plugin to version 1.0.86 or later.
Who is affected by CVE-2023-50860?
CVE-2023-50860 affects users of the Booking for Appointments and Events Calendar – Amelia plugin versions up to and including 1.0.85.
What type of vulnerability is CVE-2023-50860?
CVE-2023-50860 is categorized as a Stored Cross-site Scripting (XSS) vulnerability.
Can CVE-2023-50860 lead to data theft?
Yes, exploitation of CVE-2023-50860 could potentially allow attackers to steal user data or perform actions on behalf of users.