WordPress Plugin Vulnerabilities
BA Book Everything < 1.3.25 - Unauthenticated Reflected XSS & XFS
Description
An Unauthenticated Reflected XSS & XFS vulnerabilities was discovered in the BA Book Everything plugin v1.3.24 for WordPress.
Vulnerable parameter(s): date_from, date_to.
Proof of Concept
Affects Plugins
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Ex.Mi
Submitter
Ex.Mi
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2020-11-12 (about 5 years ago)
Added
2020-11-12 (about 5 years ago)
Last Updated
2020-11-14 (about 5 years ago)