Reflected Cross-Site Scripting Vulnerability in Amelia Plugin for WordPress
CVE-2024-1484
6.1MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 13 March 2024
What is CVE-2024-1484?
The Amelia plugin for WordPress, used for managing bookings for appointments and events, is susceptible to reflected cross-site scripting due to inadequate input sanitization and output escaping. Specifically, attackers can exploit this vulnerability through date parameters, allowing them to inject arbitrary scripts into web pages. If users are deceived into clicking a malicious link, the injected scripts can execute in their browsers, potentially leading to severe security risks, including unauthorized data access or session hijacking.
Affected Version(s)
Booking for Appointments and Events Calendar – Amelia * <= 1.0.98