Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-68538
HistoryJan 05, 2022 - 12:00 a.m.

WordPress plugin Booking Calendar cross-site scripting vulnerability

2022-01-0500:00:00
China National Vulnerability Database
www.cnvd.org.cn
7

0.001 Low

EPSS

Percentile

40.2%

WordPress is a set of blogging platform developed using PHP language. A cross-site scripting vulnerability exists in the WordPress plugin Booking Calendar. The vulnerability stems from the program not cleaning and escaping the Booking_type parameter before exporting it back to the administration page. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

CPENameOperatorVersion
wordpress booking calendarlt8.9.2

0.001 Low

EPSS

Percentile

40.2%