Vulnerabilities > TMS Outsource > Amelia > 1.0.98

DATE CVE VULNERABILITY TITLE RISK
2024-06-21 CVE-2024-6225 Cross-site Scripting vulnerability in Tms-Outsource Amelia
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.5 (and 7.5.1 for the Pro version) due to insufficient input sanitization and output escaping.
network
low complexity
tms-outsource CWE-79
4.8