Reflected Cross-Site Scripting in Bus Ticket Booking Plugin for WordPress
CVE-2023-4067
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 August 2023
What is CVE-2023-4067?
The Bus Ticket Booking with Seat Reservation plugin for WordPress is susceptible to Reflected Cross-Site Scripting due to inadequate input validation and output encoding. Attackers can exploit this vulnerability by manipulating the 'tab_date' and 'tab_date_r' parameters in versions up to 5.2.3. If exploited, this allows unauthenticated individuals to inject malicious scripts into web pages, which may execute in the user's browser upon interaction, potentially leading to session hijacking or unauthorized actions on behalf of the user.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Bus Ticket Booking with Seat Reservation * <= 5.2.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved