WordPress Booking Package Plugin <= 1.6.01 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-39918
7.1HIGH
What is CVE-2023-39918?
The Booking Package plugin by SAASPROJECT is susceptible to a reflected Cross-Site Scripting (XSS) vulnerability that allows unauthorized attackers to inject scripts into web pages. This risk arises when users interact with reflective inputs, potentially leading to the execution of malicious scripts in a user's browser. It is essential for users of the affected versions to implement patches or updates to mitigate this security issue.
Affected Version(s)
Booking Package <= 1.6.01