The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2023-10-16T08:32:45.562Z

Updated: 2023-10-16T08:32:45.562Z

Reserved: 2023-08-30T11:56:05.067Z


Link: CVE-2023-4620

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-10-16T09:15:11.627

Modified: 2023-11-07T04:22:47.757


Link: CVE-2023-4620

JSON object: View

cve-icon Redhat Information

No data.

CWE

No CWE.