Booking.com Product Helper [bookingcom-product-helper] < 1.0.2
unknown
[en] The Booking.com Product Helper WordPress plugin before 1.0.2 does not sanitize and escape Product Code when creating Product Shortcode, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- Affected:
- up to 1.0.2
- Fixed in:
- 1.0.2
- Disclosed:
- Nov 8, 2021
CVE-2021-24645 on NVD →
Booking.com Product Helper <= 1.0.1 - Cross-Site Scripting
medium
The Booking.com Product Helper WordPress plugin before 1.0.2 does not sanitize and escape Product Code when creating Product Shortcode, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- CVSS:
- 4.8
- Affected:
- up to 1.0.2
- Fixed in:
- 1.0.2
- Disclosed:
- Oct 5, 2021
CVE-2021-24645 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database