CVE-2021-36855
WordPress Booking Ultra Pro plugin <= 1.1.4 - Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro plugin <= 1.1.4 at WordPress.
Una vulnerabilidad de tipo Cross-Site Scripting (XSS) por medio de Cross-Site Request Forgery (CSRF) en el plugin Booking Ultra Pro versiones anteriores a 1.1.4 incluyéndola, en WordPress
The Booking Ultra Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.6. This is due to missing or incorrect nonce validation on most AJAX actions. This makes it possible for unauthenticated attackers to inject malicious JavaScript, obtain information about staff users, change opening times and more, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-07-19 CVE Reserved
- 2022-09-29 CVE Published
- 2024-09-17 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (2)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bookingultrapro Search vendor "Bookingultrapro" | Booking Ultra Pro Appointments Booking Calendar Search vendor "Bookingultrapro" for product "Booking Ultra Pro Appointments Booking Calendar" | <= 1.1.4 Search vendor "Bookingultrapro" for product "Booking Ultra Pro Appointments Booking Calendar" and version " <= 1.1.4" | wordpress |
Affected
|