Vulnerabilities > Codepeople > WP Time Slots Booking Form > Low
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-03-07 | CVE-2022-0389 | Cross-site Scripting vulnerability in Codepeople WP Time Slots Booking Form The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | 3.5 |