← back
CVE-2023-4620medium

Booking Calendar < 9.7.3.1 - Unauthenticated Stored XSS

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.1epss 0.5%
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N