WordPress 的 Booking Calendar 插件在所有 11.8.2 及更早版本中,由于输入清理不足且输出未转义,存在通过 'options' 参数触发的反射型跨站脚本(Reflected Cross-Site Scripting)漏洞。这使得未经身份验证的攻击者可以注入任意 Web 脚本,只要他们能够诱骗用户执行某些操作(例如点击链接),这些脚本便会在相应页面中执行。此外,由于 'booking_is_nonce_at_front_end' 选项默认处于禁用状态,nonce 检查机制默认被绕过,允许
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wpdevelop | Booking Calendar | ≤ 11.8.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpdevelop | Booking Calendar | 0 ~ 11.8.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet