Arbitrary File Upload Vulnerability in BookingPress Plugin
CVE-2024-3022
7.2HIGH
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 4 April 2024
Summary
The BookingPress plugin for WordPress presents a critical security issue related to its 'bookingpress_process_upload' function, where inadequate filename validation allows for arbitrary file uploads. This vulnerability is particularly concerning for authenticated users, especially those with administrator privileges, as it could lead to the uploading of malicious files onto the server. Once an unauthorized file is executed, it opens up the potential for remote code execution, posing significant risks to the integrity and security of the affected WordPress sites hosted with this plugin.
Affected Version(s)
BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin * <= 1.0.87
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Credit
Dian Sun