CVE-2024-47638
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2024-47638 is a newly identified Cross-site Scripting (XSS) vulnerability affecting the Online Booking & Scheduling Calendar plugin for WordPress by vCita. This issue enables an attacker to inject malicious scripts into web pages generated by the plugin, potentially leading to theft of user data or session hijacking. Affected versions of the plugin range from the unspecified older versions up to and including 4.4.6. It is crucial for WordPress users with this plugin installed to update to the latest version as soon as possible to mitigate the risk of exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.