Input validation vulnerability in Booking Calendar Contact Form 1.2.40

The Booking Calendar Contact Form plugin for WordPress is vulnerable to a type of attack called Reflected Cross-Site Scripting. This attack could allow an unauthenticated attacker to inject malicious code into a website page. When a user visits this page, the code will be executed and can do things like steal information or take control of the user’s computer. This vulnerability affects versions of the plugin up to and including version 1.2.40 and is due to the plugin not properly sanitizing and escaping user input.

Detected in:

Booking Calendar Contact Form fixed vulnerable versions: >= * <= 1.2.40

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.