WordPress Plugin Vulnerabilities

BA Book Everything < 1.3.25 - Unauthenticated Reflected XSS & XFS

Description

An Unauthenticated Reflected XSS & XFS vulnerabilities was discovered in the BA Book Everything plugin v1.3.24 for WordPress.

Vulnerable parameter(s): date_from, date_to.

Proof of Concept

Affects Plugins

Fixed in 1.3.25

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Ex.Mi
Submitter
Ex.Mi
Submitter website
Verified
Yes

Timeline

Publicly Published
2020-11-12 (about 5 years ago)
Added
2020-11-12 (about 5 years ago)
Last Updated
2020-11-14 (about 5 years ago)

Other