CVE-2022-1007: Elbtide Advanced Booking Calendar
Medium severity, CVSS 6.1. EPSS: 1.9% chance of exploitation in the next 30 days.
The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue
Affected products
- Elbtide Advanced Booking Calendar: before 1.7.1 (fixed in 1.7.1)
Published 2022-04-11. Last modified 2026-06-17.