What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CodePeople WP Time Slots Booking Form plugin <= 1.1.81 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CodePeople WP Time Slots Booking Form plugin <= 1.1.81 versions.
Explanation of Vulnerability in Simple Terms
WP Time Slots Booking Form versions up to 1.1.81 contain a stored cross-site scripting (XSS) vulnerability. An authenticated administrator with high privileges can inject malicious scripts into the plugin that execute in other users' browsers when they view affected pages. The vulnerability requires user interaction and can affect the site's integrity and confidentiality.
What an attacker can do
Inject malicious scripts that execute in other users' browsers when they view the booking form.
Potential impact on your site
An admin account compromise could allow script injection affecting site visitors and other users' sessions.
Conditions required to exploit
Attacker must have administrator-level access to the WordPress site and the victim must view an affected page.
Key dates
External resources
Related vulnerabilities