cleantalk
Vulnerabilities and Security Researches

Appointment Bookings for Zoom GoogleMeet and more – Wappointment, a2b816a4-9faf-40ea-a81d-88687f99de77

Published on
-
Research Description
Appointment Bookings for Zoom GoogleMeet and more &#8211; Wappointment [wappointment] < 2.2.5 Wappointment &lt; 2.2.5 - Unauthenticated Stored Cross-Site Scripting The plugin does not sanitise the name parameter when booking an appointment, leading to a Stored Cross-Site Scripting issue which is triggered when an admin view the Calendar.
Affected versions
max 2.2.5.
Status
vulnerable