Security Advisory

CVE-2021-24930

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-12-06 15:55:32
Last updated 2024-08-03 19:49:14
Assigner WPScan
State PUBLISHED

Description

The WordPress Online Booking and Scheduling Plugin WordPress plugin before 20.3.1 does not escape the Staff Full Name field before outputting it back in a page, which could lead to a Stored Cross-Site Scripting issue