CVE Database /
CVE-2017-2151
CVE · Medium
CVE-2017-2151 — Booking Calendar [booking] <= 7.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2017-2151
|
Booking Calendar [booking] <= 7.1 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 7.1
|
7.1 |
2017-04-20 |
—
|
CVE-2017-2151
The Booking Calendar WordPress plugin up to version 7.1 contains a stored cross-site scripting flaw that allows attackers to inject and execute malicious scripts. This vulnerability was discovered by Satoshi Takagi from Tokyo Denki University's Cryptography Laboratory and reported through Japan's coordinated vulnerability disclosure process involving JPCERT/CC and the plugin developer.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings