CVE Database /
CVE-2024-7877
CVE · Medium
CVE-2024-7877 — Simply Schedule Appointments [simply-schedule-appointments] < 1.6.7.55
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-7877
|
Simply Schedule Appointments [simply-schedule-appointments] < 1.6.7.55 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
4.8
|
< 1.6.7.55
|
1.6.7.55 |
2024-10-15 |
—
|
CVE-2024-7877
A vulnerability exists in the Appointment Booking Calendar plugin for WordPress, affecting versions up to 1.6.7.53. The issue arises from inadequate validation of input data and failure to properly prevent malicious code injection when configuring notification settings. As a result, authorized attackers with elevated permissions can embed malicious scripts that will be executed whenever users access specific pages on affected multi-site installations or those where unfiltered HTML is restricted.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings