WordPress 插件 “Appointment Hour Booking – Booking Calendar”(预约时间预订 – 预订日历)在所有版本中(包括且限于 1.5.97 及更早版本)存在存储型 DOM 跨站脚本(Stored DOM-Based XSS)漏洞。该漏洞源于输入净化不足以及输出转义不当,具体通过预订表单的单行字段(Single-Line Field)经由日程日历列表渲染器(Schedule Calendar List Renderer)触发。 这使得未经身份验证的攻击者能够向页面中注入任
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| codepeople | Appointment Hour Booking – Booking Calendar | 0 ~ 1.5.97 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100179 | 6.1 MEDIUM | Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL P |
| CVE-2026-100184 | 4.7 MEDIUM | Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL Q |
No comments yet