CVE-2019-14791: Codepeople Appointment Booking Calendar

Medium severity, CVSS 6.1. EPSS: 1.4% chance of exploitation in the next 30 days.

The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.

Affected products

  • Codepeople Appointment Booking Calendar: version 1.3.18 only

Published 2019-08-09. Last modified 2026-06-17.