Medium severity6.1NVD Advisory· Published Oct 16, 2023· Updated Jun 17, 2026
CVE-2023-4620
CVE-2023-4620
Description
The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <9.7.3.1
- cpe:2.3:a:wpbookingcalendar:booking_calendar:*:*:*:*:*:wordpress:*:*Range: <9.7.3.1
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/084e9494-2f9e-4420-9bf7-78a1a41433d7nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.