CVE-2024-7876

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Nov 5, 2024
Updated: Nov 6, 2024
CWE ID 79

Summary

CVE-2024-7876 is a vulnerability affecting the Simply Schedule Appointments Booking Plugin for WordPress. Before version 1.6.7.55, the plugin failed to sanitize and escape certain Appointment Type settings, making it susceptible to Cross-Site Scripting (XSS) attacks. High privilege users, including administrators, could exploit this issue to inject malicious scripts, potentially leading to unauthorized actions or data theft. Even when the 'unfiltered_html' setting is disabled, this vulnerability can still pose a significant security risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share