Beta

Report

Hospital Management System <= 47.0(20-11-2023) is vulnerable to Cross Site Scripting (XSS) vulnerability

Unauthenticated
Published
2025-04-21

The Hospital Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in version * -47.0(20-11-2023) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS

Score:7.1

Severity:High

Version: 47.0(20-11-2023)

The plugin vendor has not patched this vulnerability at the moment.