CVE-2015-7320: Codepeople Appointment Booking Calendar
Medium severity, CVSS 4.3. EPSS: 2.1% chance of exploitation in the next 30 days.
Multiple cross-site scripting (XSS) vulnerabilities in cpabc_appointments_admin_int_bookings_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected products
- Codepeople Appointment Booking Calendar: up to and including 1.1.7
Published 2015-09-29. Last modified 2026-06-17.