Record summary

CVE-2024-12737 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The WP BASE Booking of Appointments, Services and Events WordPress plugin before 5.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 26, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

WP BASE Booking of Appointments, Services and Events

Default status: unaffected

CVE ListBefore 5.0.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWP BASE Booking - Reflected XSSCVSS 6.1

WP BASE Booking of Appointments, Services and Events WordPress plugin < 5.0.0 contains a reflected cross-site scripting caused by lack of sanitization and escaping of a parameter before output, letting attackers execute malicious scripts in high privilege users' browsers, exploit requires victim to load a maliciously crafted URL.

Impact

Attackers can execute malicious scripts in high privilege users' browsers, potentially leading to session hijacking or account compromise.

Remediation

Update to version 5.0.0 or later.

WeaknessesCWE-79
AuthorsSourabh-Sahu
Template tagscvecve2024wp-basewordpresswpscanwp-pluginwpauthenticatedxsswp-base-booking-of-appointments-services-and-events
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:wp-base:wp_base_booking_of_appointments\,_services_and_events:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2