CVE-2023-4620: medium-severity vulnerability in Booking Calendar
Booking Calendar < 9.7.3.1 - Unauthenticated Stored XSS
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.1epss 0.6%
exploitation probability
0.6%top 55% of all CVEs
observed exploitation
nono source reports it
The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
Unknown · Booking CalendarRelated CVEs — Booking Calendar
In the same product, most dangerous first.
CVE-2021-25040—Booking Calendar < 8.9.2 - Reflected Cross-Site ScriptingEPSS 0.8%CVE-2026-105195LOWBooking Calendar 10.15 - 11.8.2 - Editor+ Arbitrary Option DisclosureEPSS —CVE-2026-105193MEDIUMBooking Calendar < 11.8 - Unauthenticated Booking Information Disclosure and Modification via Predictable Booking HashEPSS —