CVE · Medium

CVE-2024-10893 — Booking Calendar [booking] < 10.6.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10893 Booking Calendar [booking] < 10.6.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 10.6.5 10.6.5 2024-11-14

CVE-2024-10893

The WP Booking Calendar plugin through version 10.6.4 contains a stored cross-site scripting vulnerability in its administrator settings caused by inadequate sanitization of inputs and escaping of outputs. Administrators and higher-level users can inject malicious scripts that will execute when other users view affected pages. This vulnerability only impacts multi-site WordPress installations or those where the unfiltered_html capability has been disabled.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.