Products
WP Booking
- before 2.4.5
Source
vultures@jpcert.or.jp
Tags
CVE-2024-35297 details
Published : May 27, 2024, 5:15 a.m.
Last Modified : May 27, 2024, 5:15 a.m.
Last Modified : May 27, 2024, 5:15 a.m.
Description
Cross-site scripting vulnerability exists in WP Booking versions prior to 2.4.5. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing the web site using the product.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|
References
URL | Source |
---|---|
https://jvn.jp/en/jp/JVN35838128/ | vultures@jpcert.or.jp |
https://plugins.trac.wordpress.org/changeset?new=3084990%40wp-easy-booking%2Ftrunk%2Fview%2Ffrontend%2Fbooking-locations.php&old=2404687%40wp-easy-booking%2Ftrunk%2Fview%2Ffrontend%2Fbooking-locations.php | vultures@jpcert.or.jp |
https://wordpress.org/plugins/wp-easy-booking/ | vultures@jpcert.or.jp |
This website uses the NVD API, but is not approved or certified by it.