The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin (or editor depending on Salon booking system WordPress plugin through 9.6.5 configuration) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Metrics
Affected Vendors & Products
References
History
Fri, 18 Apr 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Salonbookingsystem
Salonbookingsystem salon Booking System |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:salonbookingsystem:salon_booking_system:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Salonbookingsystem
Salonbookingsystem salon Booking System |

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-01T19:18:48.123Z
Reserved: 2024-03-18T15:24:49.174Z
Link: CVE-2024-2603

Updated: 2024-08-01T19:18:48.123Z

Status : Analyzed
Published: 2024-04-26T05:15:50.163
Modified: 2025-04-18T18:42:37.867
Link: CVE-2024-2603

No data.