Описание
The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.
The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2019-14791
- https://wordpress.org/plugins/appointment-booking-calendar/#developers
- https://wpvulndb.com/vulnerabilities/9426
- https://www.pluginvulnerabilities.com/2019/07/03/hackers-look-to-be-targeting-the-wordpress-plugin-appointment-booking-calendar-which-is-yet-another-insecure-plugin-from-code-people
Связанные уязвимости
CVSS3: 6.1
nvd
больше 6 лет назад
The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.