Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin Unauthenticated Arbitrary Shortcode Execution Vulnerability
Vulnerability
A vulnerability allowing unauthenticated arbitrary shortcode execution has been identified in the Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin for WordPress, affecting all versions through 1.6.8.5. The issue arises because the plugin does not properly validate user input before executing shortcodes, allowing attackers to exploit this lack of validation.
Impact
Exploitation of this vulnerability could lead to unauthorized execution of shortcodes, which may be used to inject malicious content or scripts that could be executed within the WordPress environment.
Remediation
Users are advised to update the Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin to version 1.6.8.7 or a newer patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
