CVE Database /
CVE-2024-7876
CVE · Medium
CVE-2024-7876 — Simply Schedule Appointments [simply-schedule-appointments] < 1.6.7.55
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-7876
|
Simply Schedule Appointments [simply-schedule-appointments] < 1.6.7.55 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
4.8
|
< 1.6.7.55
|
1.6.7.55 |
2024-10-15 |
—
|
CVE-2024-7876
A WordPress plugin called Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin contains a security flaw that allows malicious code injection through admin appointment settings, specifically affecting versions 1.6.7.53 and earlier. The issue arises from inadequate filtering of user input and insufficient protection against script execution on the affected pages. This vulnerability is confined to multi-site installations where certain HTML restrictions are in place.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings