Reflected Cross-Site Scripting Vulnerability in Amelia Plugin for WordPress
CVE-2024-1484
6.1MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 13 March 2024
Summary
The Amelia plugin for WordPress, used for managing bookings for appointments and events, is susceptible to reflected cross-site scripting due to inadequate input sanitization and output escaping. Specifically, attackers can exploit this vulnerability through date parameters, allowing them to inject arbitrary scripts into web pages. If users are deceived into clicking a malicious link, the injected scripts can execute in their browsers, potentially leading to severe security risks, including unauthorized data access or session hijacking.
Affected Version(s)
Booking for Appointments and Events Calendar – Amelia * <= 1.0.98
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Muhammad Hassham Nagori