CVE-2024-47638

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Oct 5, 2024
Updated: Oct 7, 2024
CWE ID 79

Summary

CVE-2024-47638 is a newly identified Cross-site Scripting (XSS) vulnerability affecting the Online Booking & Scheduling Calendar plugin for WordPress by vCita. This issue enables an attacker to inject malicious scripts into web pages generated by the plugin, potentially leading to theft of user data or session hijacking. Affected versions of the plugin range from the unspecified older versions up to and including 4.4.6. It is crucial for WordPress users with this plugin installed to update to the latest version as soon as possible to mitigate the risk of exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share