plugin

Business Hours Indicator Vulnerabilities

1 known security issue reported for the Business Hours Indicator WordPress plugin. Most recent disclosed Aug 2, 2021.

1 medium

Running Business Hours Indicator on your site? Check whether your installed version is affected.

Scan your site free

Business Hours Indicator <= 2.3.4 - Authenticated Stored Cross-Site Scripting

medium

The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its 'Now closed message" setting when outputting it in the backend and frontend, leading to an Authenticated Stored Cross-Site Scripting issue

CVSS:
6.4
Affected:
up to 2.3.5
Fixed in:
2.3.5
Disclosed:
Aug 2, 2021

CVE-2021-24593 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database