CVE-2024-2603: Salon booking system <= 9.6.5 - Editor+ Stored XSS via Email Settings
The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin (or editor depending on Salon booking system WordPress plugin through 9.6.5 configuration) to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2603?
CVE-2024-2603 has a moderate severity level due to its potential for allowing high privilege users to perform Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-2603?
To fix CVE-2024-2603, update the Salon booking system WordPress plugin to version 9.6.6 or later, where the vulnerability is addressed.
Who is affected by CVE-2024-2603?
CVE-2024-2603 affects users of the Salon booking system WordPress plugin version 9.6.5 and earlier, particularly those with high privilege roles.
What types of attacks can CVE-2024-2603 enable?
CVE-2024-2603 can enable Stored Cross-Site Scripting attacks, which may allow attackers to execute scripts in the context of a user's session.
What systems are at risk with CVE-2024-2603?
Any WordPress site utilizing the Salon booking system plugin version 9.6.5 or earlier is at risk from CVE-2024-2603.