Aug. 2, 2023, 9:15 a.m. |

National Vulnerability Database web.nvd.nist.gov

The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_date' and 'tab_date_r' parameters in versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

attackers booking bus cross-site cve inject input plugin scripting scripts ticket vulnerable web wordpress

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Engineering Practice Lead

@ NCC Group | GBR Manchester Hardman Boulevard

Senior Cyber Security Engineer - Cloud & Multifactor Authentication

@ General Motors | GM Global Technical Center - Michigan IT Innovation Center