WordPress security changelog
MEDIUM CVE-2021-24712 Modified

Appointment Hour Booking: A security weakness

Appointment Hour Booking is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

CVE / CNA score 5.4 CVSS · contact@wpscan.com
NVD score 5.4 CVSS 3.1 · nvd@nist.gov
Component
Appointment Hour Booking
Plugin slug
appointment-hour-booking
Affected
See vendor advisory
Safe version
See mitigation notes
Published
Oct 11, 2021
Weakness
CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

This CVE was published Oct 11, 2021 and is one of 12 known issues for this plugin.

Patch or disable the affected component.

Update Appointment Hour Booking to a release outside the affected range, or disable and remove it until a fixed version is available.

Technical description

The Appointment Hour Booking WordPress plugin before 1.3.17 does not properly sanitize values used when creating new calendars.

NVD vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Primary and upstream sources