Ultimate Appointment Booking & Scheduling [ultimate-appointment-scheduling] < 1.1.10
unknown
Authenticated Cross-Site Scripting (XSS) vulnerability found by zerodetail & ratherbland in WordPress Ultimate Appointment Booking & Scheduling plugin (versions <= 1.1.9).
- Affected:
- up to 1.1.10
- Fixed in:
- 1.1.10
- Disclosed:
- Aug 27, 2020
Ultimate Appointment Booking & Scheduling [ultimate-appointment-scheduling] < 1.1.10
unknown
[en] Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointment_ID" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.
- Affected:
- up to 1.1.10
- Fixed in:
- 1.1.10
- Disclosed:
- Aug 26, 2020
CVE-2020-24313 on NVD →
Ultimate Appointment Booking & Scheduling < 1.1.10 - Reflected Cross-Site Scripting
medium
Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointment_ID" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.
- CVSS:
- 6.1
- Affected:
- up to 1.1.10
- Fixed in:
- 1.1.10
- Disclosed:
- Aug 10, 2020
CVE-2020-24313 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database