CVE-2025-24723: WordPress Booking Calendar Contact Form Plugin <= 1.2.55 - Stored Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Booking Calendar Contact Form booking-calendar-contact-form allows Stored XSS.This issue affects Booking Calendar Contact Form: from n/a through <= 1.2.55.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24723?
CVE-2025-24723 is classified as a high severity vulnerability due to its potential for Stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-24723?
To fix CVE-2025-24723, update the CodePeople Booking Calendar Contact Form to version 1.2.56 or later.
What type of vulnerability is CVE-2025-24723?
CVE-2025-24723 is an Improper Neutralization of Input During Web Page Generation, causing Stored XSS.
Which software is affected by CVE-2025-24723?
CVE-2025-24723 affects the CodePeople Booking Calendar Contact Form and the WordPress Booking Calendar Contact Form Plugin versions up to 1.2.55.
Can CVE-2025-24723 compromise user data?
Yes, CVE-2025-24723 can compromise user data by enabling attackers to inject malicious scripts that execute on the client side.