CVE-2024-35761: WordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.4.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in vCita Online Booking & Scheduling Calendar for WordPress by vcita allows Stored XSS.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.4.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35761?
CVE-2024-35761 is classified with a high severity due to the potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2024-35761?
To fix CVE-2024-35761, update the vCita Online Booking & Scheduling Calendar for WordPress to version 4.4.1 or later.
What types of attacks can CVE-2024-35761 facilitate?
CVE-2024-35761 can facilitate stored XSS attacks, allowing attackers to inject malicious scripts into web pages.
Which versions of the vCita plugin are affected by CVE-2024-35761?
CVE-2024-35761 affects versions prior to 4.4.1 of the vCita Online Booking & Scheduling Calendar for WordPress.
Is CVE-2024-35761 a common vulnerability?
Yes, CVE-2024-35761 is a common vulnerability type that exploits improper input handling, prevalent in web applications.