CVE-2024-8663

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Sep 13, 2024
CWE ID 79

Summary

CVE-2024-8663 identifies a Reflected Cross-Site Scripting vulnerability in the WP Simple Booking Calendar plugin for WordPress, affecting all versions up to and including 2.0.10. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts into pages, potentially compromising user interactions if they are misled into clicking malicious links. To remediate this issue, it is recommended that users update the plugin to the latest version released after 2.0.10, which addresses this flaw. The exploit's severity is rated as medium with an exploitability score of 2.8, indicating that user interaction is required for successful exploitation while having low integrity and confidentiality impacts. Organizations utilizing this plugin should take prompt action to mitigate potential risks associated with this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share