CVE-2024-12077: Booking Calendar and Booking Calendar Pro <= Multiple Versions - Reflected Cross-Site Scripting via 'calendar_id'
The Booking Calendar and Booking Calendar Pro plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the ‘calendarid’ parameter in all versions up to, and including, 3.2.19 and 11.2.19 respectively, due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12077?
CVE-2024-12077 is classified as a medium severity vulnerability due to the potential for reflected cross-site scripting.
How do I fix CVE-2024-12077?
To fix CVE-2024-12077, you should update the Booking Calendar plugin to version 3.2.20 or higher and the Booking Calendar Pro plugin to version 11.2.20 or higher.
What are the affected versions for CVE-2024-12077?
CVE-2024-12077 affects all versions of Booking Calendar up to and including 3.2.19 and Booking Calendar Pro up to and including 11.2.19.
Can CVE-2024-12077 be exploited remotely?
Yes, CVE-2024-12077 can be exploited remotely due to the reflected nature of the cross-site scripting vulnerability.
What are the potential impacts of CVE-2024-12077?
The potential impacts of CVE-2024-12077 include unauthorized script execution in the context of vulnerable users, leading to session hijacking or data theft.