CVE-2021-24930
06.12.2021, 16:15
The WordPress Online Booking and Scheduling Plugin WordPress plugin before 20.3.1 does not escape the Staff Full Name field before outputting it back in a page, which could lead to a Stored Cross-Site Scripting issue
Vendor | Product | Version |
---|---|---|
booking-wp-plugin | bookly | 𝑥 < 20.3.1 |
𝑥
= Vulnerable software versions