Unrated severityNVD Advisory· Published Jun 13, 2022· Updated Aug 3, 2024
Appointment Hour Booking < 1.3.56 - Admin+ Stored Cross-Site Scripting
CVE-2022-1710
Description
The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <1.3.56
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/ed162ccc-88e6-41e8-b24d-1b9f77a038b6mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.