WordPress Booking Calendar Contact Form 1.0.23 Privilege Escalation Stored XSS
Vulnerability Description
WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabilities that allow authenticated users to modify plugin options and inject malicious scripts by failing to verify user privileges and sanitize input parameters. Attackers with subscriber-level accounts can inject XSS payloads through parameters like price, name, calendar_language, and email_confirmation_to_user via admin-ajax.php and admin.php endpoints to execute arbitrary JavaScript in administrator browsers.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-20070
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Joaquin Ramirez Martinez [ i0 SEC-LABORATORY ]
References
More from dwbooster
View All →Affected Vendor
dwbooster
View all reports →