WordPress Plugin Vulnerabilities
Ultimate Appointment Booking & Scheduling < 1.1.10 - Authenticated Cross-Site Scripting (XSS)
Description
The Ultimate Appointment Booking & Scheduling WordPress plugin, versions 1.1.9 and older, were vulnerable to Authenticated Cross-Site Scripting (XSS) within multiple parameters.
Proof of Concept
Affects Plugins
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
zerodetail & ratherbland
Verified
No
WPVDB ID
Timeline
Publicly Published
2020-08-10 (about 5 years ago)
Added
2020-08-26 (about 5 years ago)
Last Updated
2020-08-27 (about 5 years ago)