Session Fixation in alextselegidis/easyappointments
CVE-2023-2105
8.8HIGH
What is CVE-2023-2105?
The EasyAppointments plugin, maintained by Alex Tselegidis, contains a vulnerability that allows for session fixation prior to version 1.5.0. This flaw could potentially compromise user session security, enabling an attacker to hijack valid user sessions. Users are urged to update their installations to the latest version to mitigate the risks associated with this vulnerability.
Affected Version(s)
alextselegidis/easyappointments < 1.5.0
