Vulnerabilities > Codepeople > WP Time Slots Booking Form > Low

DATE CVE VULNERABILITY TITLE RISK
2022-03-07 CVE-2022-0389 Cross-site Scripting vulnerability in Codepeople WP Time Slots Booking Form
The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
network
codepeople CWE-79
3.5