CVE · Medium

CVE-2017-2151 — Booking Calendar [booking] <= 7.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2017-2151 Booking Calendar [booking] <= 7.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 7.1 7.1 2017-04-20

CVE-2017-2151

The Booking Calendar WordPress plugin up to version 7.1 contains a stored cross-site scripting flaw that allows attackers to inject and execute malicious scripts. This vulnerability was discovered by Satoshi Takagi from Tokyo Denki University's Cryptography Laboratory and reported through Japan's coordinated vulnerability disclosure process involving JPCERT/CC and the plugin developer.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.