Reflected Cross-Site Scripting in WP BASE Booking for WordPress
CVE-2024-12469
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 17 December 2024
What is CVE-2024-12469?
CVE-2024-12469 describes a critical reflected cross-site scripting (XSS) vulnerability in the WP BASE Booking of Appointments, Services and Events plugin for WordPress. This vulnerability affects all versions up to and including 4.9.1 and arises from inadequate input sanitization and output escaping via the āstatusā parameter. An attacker can exploit this vulnerability to insert arbitrary web scripts, which can be executed by unsuspecting users who are manipulated into clicking a specially crafted link. As this vulnerability does not require any authentication, it poses a significant risk to users, potentially leading to data theft, session hijacking, and other malicious activities.
Affected Version(s)
WP BASE Booking of Appointments, Services and Events * <= 4.9.1