Medium severity6.4NVD Advisory· Published Jun 15, 2026· Updated Jun 15, 2026
CVE-2016-20070
CVE-2016-20070
Description
WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabilities that allow authenticated users to modify plugin options and inject malicious scripts by failing to verify user privileges and sanitize input parameters. Attackers with subscriber-level accounts can inject XSS payloads through parameters like price, name, calendar_language, and email_confirmation_to_user via admin-ajax.php and admin.php endpoints to execute arbitrary JavaScript in administrator browsers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2= 1.0.23+ 1 more
- (no CPE)range: = 1.0.23
- (no CPE)range: =1.0.23
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.