CVE-2024-9882: Salon Booking System < 10.9.4 - Admin+ Stored XSS
The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9882?
CVE-2024-9882 is classified as a high severity vulnerability.
How do I fix CVE-2024-9882?
To fix CVE-2024-9882, update the Salon Booking System plugin to version 1.9.4 or later.
Who is affected by CVE-2024-9882?
CVE-2024-9882 affects users of the Salon Booking System WordPress plugin prior to version 1.9.4.
What type of attacks can CVE-2024-9882 allow?
CVE-2024-9882 can allow high privilege users to perform Stored Cross-Site Scripting (XSS) attacks.
What is the impact of CVE-2024-9882?
The impact of CVE-2024-9882 includes the potential for malicious users to inject harmful scripts into the application.