WordPress Easy Appointments plugin <= 3.10.7 - Auth. Stored Cross-Site Scripting (XSS) vulnerability
CVE-2023-30748
What is CVE-2023-30748?
The Easy Appointments plugin by Nikola Loncar is susceptible to a Cross-site Scripting (XSS) vulnerability due to improper neutralization of user input during web page generation. This flaw allows attackers to exploit the application by injecting malicious scripts that can be stored and later executed in the browsers of unsuspecting users. Users of affected versions should be vigilant, as the consequences of this vulnerability can lead to unauthorized access to sensitive user information, session hijacking, and various other malicious activities. Ensuring that the plugin is updated to mitigate this issue is essential for maintaining application security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Easy Appointments <= 3.10.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved