Reflected Cross-Site Scripting Vulnerability in Amelia Plugin for WordPress
CVE-2024-1484

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
13 March 2024

Summary

The Amelia plugin for WordPress, used for managing bookings for appointments and events, is susceptible to reflected cross-site scripting due to inadequate input sanitization and output escaping. Specifically, attackers can exploit this vulnerability through date parameters, allowing them to inject arbitrary scripts into web pages. If users are deceived into clicking a malicious link, the injected scripts can execute in their browsers, potentially leading to severe security risks, including unauthorized data access or session hijacking.

Affected Version(s)

Booking for Appointments and Events Calendar – Amelia * <= 1.0.98

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Hassham Nagori
.