Unauthenticated Booking Manipulation in WP Booking Calendar by WordPress
CVE-2024-13821
5.3MEDIUM
Summary
The WP Booking Calendar plugin is subject to a vulnerability that allows unauthenticated users to manipulate confirmed bookings without adequate re-verification. This issue affects all plugin versions up to and including 10.10. By exploiting this flaw, attackers can alter their bookings even after approval, as the plugin does not enforce the necessary security checks for changes post-confirmation. Website administrators should apply the latest updates to safeguard against unauthorized booking alterations.
Affected Version(s)
WP Booking Calendar * <= 10.10
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Asaf Mozes