CVE-2024-10027: WP Booking Calendar < 10.6.3 - Admin+ Stored XSS
The WP Booking Calendar WordPress plugin before 10.6.3 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10027?
CVE-2024-10027 is considered a high severity vulnerability due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-10027?
To fix CVE-2024-10027, update the WP Booking Calendar plugin to version 10.6.3 or later.
Who is affected by CVE-2024-10027?
CVE-2024-10027 affects users of the WP Booking Calendar plugin versions prior to 10.6.3.
What kind of attacks does CVE-2024-10027 allow?
CVE-2024-10027 allows high privilege users, such as admins, to perform Stored Cross-Site Scripting attacks.
Is CVE-2024-10027 related to unfiltered_html capability?
Yes, CVE-2024-10027 can lead to vulnerabilities even when the unfiltered_html capability is disallowed.