Beveiligingsadvies

CVE-2021-24673

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2021-10-04 11:20:18
Laatst bijgewerkt 2024-08-03 19:42:16
Toegewezen door WPScan
CVSS-score geen score
Status PUBLISHED

Beschrijving

The Appointment Hour Booking WordPress plugin before 1.3.16 does not escape some of the Calendar Form settings, allowing high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.