CVE-2024-10893: WP Booking Calendar < 10.6.5 - Admin+ Stored XSS
The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10893?
CVE-2024-10893 has been classified as a high severity vulnerability due to the potential for Stored Cross-Site Scripting attacks by privileged users.
How do I fix CVE-2024-10893?
To fix CVE-2024-10893, update the WP Booking Calendar plugin to version 10.6.5 or later, which addresses the sanitization issue.
What is the impact of CVE-2024-10893 on WordPress sites?
CVE-2024-10893 could allow high privilege users to execute malicious scripts on affected WordPress sites, potentially compromising site security.
Who is affected by CVE-2024-10893?
CVE-2024-10893 affects installations of the WP Booking Calendar plugin prior to version 10.6.5 across all WordPress websites.
What types of attacks can CVE-2024-10893 enable?
CVE-2024-10893 enables Stored Cross-Site Scripting attacks, which can lead to unauthorized actions being executed on behalf of users.