S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-1007 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Advanced Booking Calendar plugin for WordPress affects v. before 1.7.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-1007
6.1
CVSS

The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Advanced Booking Calendar
AFFECTED< 1.7.1SAFE ✓≥ 1.7.1
Updated Aug 22, 2026View on NVD →
Detail

The Advanced Booking Calendar plugin for WordPress is a tool that enables website owners to manage their booking calendars more effectively. This plugin makes it easy to create, manage, and display booking schedules on their website. Users can customize their booking calendars by setting availability periods, time slots, pricing, and other relevant details.

However, the plugin has been flagged for a vulnerability identified as CVE-2022-1007. This security flaw arises due to the plugin's inability to sanitize and escape the room parameter, which leaves it exposed to Reflected Cross-Site Scripting (XSS) attacks. This means that an attacker can craft malicious scripts that end up being executed when a user interacts with a web page that contains the booking calendar.

When exploited, this vulnerability can lead to potentially disastrous consequences for website owners. For instance, attackers can gain unauthorized access to sensitive data such as user credentials, financial data, and intellectual property. They can also inject malware onto the website, which can morph into more dangerous cyberattacks like ransomware, DDoS, and SQL injections. This leaves both the website owner and their customers vulnerable to malicious attacks.

In conclusion, website owners need to be vigilant and proactive in protecting their digital assets. By subscribing to s4e.io's pro features, they can receive timely and accurate information on vulnerabilities in their digital assets, including the Advanced Booking Calendar plugin for WordPress, and quickly take the necessary precautions to secure their website. Don't wait until it's too late to act; stay ahead of the curve and protect your online business today.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners can adopt the following precautions:

  • Upgrade to the latest version of the Advanced Booking Calendar plugin (version 1.7.1 or higher).
  • Disable the plugin if it is not in use.
  • Implement a web application firewall (WAF) that can detect and block malicious scripts.
  • Use content security policies (CSP) to limit the sources of content on the website.
  • Regularly scan the website for vulnerabilities and implement industry-standard security measures.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.