WordPress Booking Calendar Contact Form Plugin <= 1.2.40 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-36384
7.1HIGH
What is CVE-2023-36384?
A reflected Cross-Site Scripting (XSS) vulnerability exists in the CodePeople Booking Calendar Contact Form plugin versions up to 1.2.40. This vulnerability allows attackers to inject malicious scripts that can execute in the context of the user's session. Successfully exploiting this vulnerability could lead to unauthorized actions on behalf of the user, compromising sensitive information and the integrity of the website.
Affected Version(s)
Booking Calendar Contact Form <= 1.2.40