Input validation vulnerability in Booking Calendar Contact Form 1.2.55

The Booking Calendar Contact Form plugin for WordPress can be easily attacked by cybercriminals. This is because it has a vulnerability called Stored Cross-Site Scripting, which is found in versions 1.2.55 and below. The reason for this vulnerability is that the plugin does not properly clean and protect the information it receives or displays. This means that hackers who have administrator-level access or higher can insert harmful scripts into pages that will be executed whenever someone visits that page. However, this only affects websites with multiple sites or have disabled the unfiltered_html feature.

Detected in:

Booking Calendar Contact Form fixed vulnerable versions: >= * <= 1.2.55

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.