Arbitrary File Upload Vulnerability in BookingPress Plugin
CVE-2024-3022
7.2HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 4 April 2024
What is CVE-2024-3022?
The BookingPress plugin for WordPress presents a critical security issue related to its 'bookingpress_process_upload' function, where inadequate filename validation allows for arbitrary file uploads. This vulnerability is particularly concerning for authenticated users, especially those with administrator privileges, as it could lead to the uploading of malicious files onto the server. Once an unauthorized file is executed, it opens up the potential for remote code execution, posing significant risks to the integrity and security of the affected WordPress sites hosted with this plugin.
Affected Version(s)
BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin * <= 1.0.87