Input validation vulnerability in Booking calendar, Appointment Booking System 3.2.15

The Booking calendar and Appointment Booking System plugin for WordPress has a security vulnerability that allows attackers to insert harmful code through SVG file uploads. This can affect all versions up to 3.2.15 because there is not enough protection in place to prevent this type of attack. As a result, unauthorized users can add malicious scripts to pages that will run when the SVG file is opened.

Detected in:

Booking calendar, Appointment Booking System open vulnerable versions: >= * <= 3.2.15

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.