cleantalk
Vulnerabilities and Security Researches

WP Booking Calendar, CVE-2023-4620

CVE, Research URL

CVE-2023-4620

Application

WP Booking Calendar

Published on
Oct 16, 2023
Research Description
The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators
Affected versions
max 9.7.4.
Status
vulnerable