Input validation vulnerability in Timely Booking Button 2.0.2

The Timely Booking Button plugin for WordPress is vulnerable to a type of attack called Stored Cross-Site Scripting. This kind of attack can allow someone who has administrator-level access to a WordPress website to inject malicious web scripts into pages that visitors to the website will see. For this vulnerability to work, the website must have the Timely Booking Button plugin installed, and must either be a multi-site installation or must have a feature called unfiltered_html disabled. The vulnerability only affects versions of the plugin up to and including 2.0.2.

Detected in:

Timely Booking Button open vulnerable versions: >= * <= 2.0.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.