Unauthenticated Booking Manipulation in WP Booking Calendar by WordPress
CVE-2024-13821
5.3MEDIUM
What is CVE-2024-13821?
The WP Booking Calendar plugin is subject to a vulnerability that allows unauthenticated users to manipulate confirmed bookings without adequate re-verification. This issue affects all plugin versions up to and including 10.10. By exploiting this flaw, attackers can alter their bookings even after approval, as the plugin does not enforce the necessary security checks for changes post-confirmation. Website administrators should apply the latest updates to safeguard against unauthorized booking alterations.
Affected Version(s)
WP Booking Calendar * <= 10.10