First published: Fri Apr 26 2024(Updated: )
The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin (or editor depending on Salon booking system WordPress plugin through 9.6.5 configuration) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Salon Booking System | <=9.6.5 | |
Salon Booking System WordPress Plugin | <9.6.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-2603 has a moderate severity level due to its potential for allowing high privilege users to perform Stored Cross-Site Scripting attacks.
To fix CVE-2024-2603, update the Salon booking system WordPress plugin to version 9.6.6 or later, where the vulnerability is addressed.
CVE-2024-2603 affects users of the Salon booking system WordPress plugin version 9.6.5 and earlier, particularly those with high privilege roles.
CVE-2024-2603 can enable Stored Cross-Site Scripting attacks, which may allow attackers to execute scripts in the context of a user's session.
Any WordPress site utilizing the Salon booking system plugin version 9.6.5 or earlier is at risk from CVE-2024-2603.