WordPress Booking Package Plugin <= 1.6.01 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-39918

7.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
4 September 2023

Summary

The Booking Package plugin by SAASPROJECT is susceptible to a reflected Cross-Site Scripting (XSS) vulnerability that allows unauthorized attackers to inject scripts into web pages. This risk arises when users interact with reflective inputs, potentially leading to the execution of malicious scripts in a user's browser. It is essential for users of the affected versions to implement patches or updates to mitigate this security issue.

Affected Version(s)

Booking Package <= 1.6.01

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Truoc Phan (Patchstack Alliance)
.