Description
WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabilities that allow authenticated users to modify plugin options and inject malicious scripts by failing to verify user privileges and sanitize input parameters. Attackers with subscriber-level accounts can inject XSS payloads through parameters like price, name, calendar_language, and email_confirmation_to_user via admin-ajax.php and admin.php endpoints to execute arbitrary JavaScript in administrator browsers.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Joaquin Ramirez Martinez [ i0 SEC-LABORATORY ]
References
www.exploit-db.com/exploits/39423 (ExploitDB-39423)
wordpress.dwbooster.com/ (Official Product Homepage)
www.vulncheck.com/...ct-form-privilege-escalation-stored-xss (VulnCheck Advisory: WordPress Booking Calendar Contact Form 1.0.23 Privilege Escalation Stored XSS)