CVE-2020-24313: Etoilewebdesign Ultimate Appointment Booking & Scheduling
Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.
Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointment_ID" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.
Affected products
- Etoilewebdesign Ultimate Appointment Booking & Scheduling: up to and including 1.1.9
Published 2020-08-26. Last modified 2026-06-17.