CVE-2023-51520: WordPress Booking Calendar Plugin < 9.7.4 is vulnerable to Cross Site Scripting (XSS)
Published Feb 1, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPdevelop / Oplugins WP Booking Calendar allows Stored XSS.This issue affects WP Booking Calendar: from n/a before 9.7.4.
Affected Software
1 affected component
Wpbookingcalendar Booking Calendar Wordpress<9.7.4
Remediation
Information
Update to 9.7.4 or a higher version.
Event History
Feb 1, 2024
CVE Published
via MITRE·11:14 AM
Data Sourced
via MITRE·11:14 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-51520?
CVE-2023-51520 is classified as a high-severity vulnerability due to its potential for Stored Cross-site Scripting (XSS).
2
How do I fix CVE-2023-51520?
To fix CVE-2023-51520, update WP Booking Calendar to version 9.7.4 or later.
3
What type of vulnerability is CVE-2023-51520?
CVE-2023-51520 is a Stored Cross-site Scripting (XSS) vulnerability that involves improper neutralization of input during web page generation.
4
What versions are affected by CVE-2023-51520?
CVE-2023-51520 affects all versions of WP Booking Calendar prior to 9.7.4.
5
Who is impacted by CVE-2023-51520?
Users of WP Booking Calendar versions before 9.7.4 are at risk due to CVE-2023-51520.