First published: Sat Jul 20 2024(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Booking Ultra Pro allows Stored XSS.This issue affects Booking Ultra Pro: from n/a through 1.1.13.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Booking Ultra Pro Plugin | <=1.1.13 | |
WordPress Appointment Booking Calendar | <=1.1.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38676 is classified as a high severity vulnerability due to its potential for stored XSS attacks.
To fix CVE-2024-38676, update Booking Ultra Pro to a version later than 1.1.13.
CVE-2024-38676 affects Booking Ultra Pro and the WordPress Appointments Booking Calendar Plugin, both up to version 1.1.13.
Cross-site Scripting, as referenced in CVE-2024-38676, allows attackers to inject malicious scripts into web pages viewed by users.
If your website uses affected versions of Booking Ultra Pro or the Appointments Booking Calendar Plugin, it could be vulnerable to exploitation through stored XSS.