CVE-2024-7877: Appointment Booking Calendar < 1.6.7.55 - Admin+ Stored XSS
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Notification settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfilteredhtml is disallowed
Affected Software
Event History
Frequently Asked Questions
What are the potential impacts of CVE-2024-7877?
CVE-2024-7877 could allow high privilege users to exploit Cross-Site Scripting vulnerabilities in the Appointment Booking Calendar plugin.
What is the recommended action to mitigate CVE-2024-7877?
To mitigate CVE-2024-7877, update the Simply Schedule Appointments Booking Plugin to version 1.6.7.55 or later.
Who is affected by CVE-2024-7877?
CVE-2024-7877 affects installations of the Simply Schedule Appointments Booking Plugin prior to version 1.6.7.55 on WordPress.
What type of vulnerability is CVE-2024-7877?
CVE-2024-7877 is categorized as a Cross-Site Scripting (XSS) vulnerability due to improper sanitization of notification settings.
Can CVE-2024-7877 be exploited remotely?
Yes, CVE-2024-7877 can potentially be exploited remotely by high privilege users on affected WordPress sites.