CVE-2024-10027
The WP Booking Calendar plugin for WordPress contains a stored cross-site scripting vulnerability in its administrative settings that affects versions 10.6.2 and earlier. Authenticated administrators can inject malicious scripts into the plugin's settings due to inadequate sanitization and escaping of user input. The vulnerability only impacts multi-site WordPress installations or those where the unfiltered_html capability has been disabled. Injected scripts execute for users viewing pages containing the malicious content.
Based on public CVE data (MITRE/NVD).