CVE-2025-48231: WordPress Booking Calendar Contact Form plugin <= 1.2.58 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Booking Calendar Contact Form allows Stored XSS. This issue affects Booking Calendar Contact Form: from n/a through 1.2.58.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Booking Calendar Contact Form booking-calendar-contact-form allows Stored XSS.This issue affects Booking Calendar Contact Form: from n/a through <= 1.2.58.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48231?
CVE-2025-48231 is classified as a medium severity vulnerability due to its potential for enabling stored cross-site scripting attacks.
How do I fix CVE-2025-48231?
To fix CVE-2025-48231, update the Booking Calendar Contact Form plugin to the latest version that addresses this vulnerability.
What impact does CVE-2025-48231 have on my website?
CVE-2025-48231 allows attackers to inject malicious scripts into web pages, potentially compromising user data and site integrity.
Which versions of Booking Calendar Contact Form are affected by CVE-2025-48231?
CVE-2025-48231 affects all versions of Booking Calendar Contact Form up to and including version 1.2.58.
Is CVE-2025-48231 specific to any platforms?
Yes, CVE-2025-48231 specifically affects the Booking Calendar Contact Form plugin used in WordPress.