Medium severity6.1NVD Advisory· Published Apr 28, 2017· Updated May 13, 2026
CVE-2017-2151
CVE-2017-2151
Description
Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected products
2- cpe:2.3:a:booking_calendar_project:booking_calendar:*:*:*:*:*:wordpress:*:*Range: <=7.1
- wpdevelop/Booking Calendarv5Range: version 7.1 and earlier
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- jvn.jp/en/jp/JVN54762089/index.htmlnvdThird Party AdvisoryVDB Entry
- wpbookingcalendar.com/changelog/nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.