All Versions Vulnerable to Arbitrary File Read to Arbitrary File Creation
CVE-2024-6467
What is CVE-2024-6467?
The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin for WordPress presents a significant security flaw due to its Arbitrary File Read and Arbitrary File Creation capabilities. Authenticated attackers with a Subscriber level of access or higher can exploit this vulnerability through the 'bookingpress_save_lite_wizard_settings_func' function. This exploitation enables them to create arbitrary files that could include sensitive server data or execute PHP code. The potential exposure includes critical sensitive information and poses severe risks to the integrity of the WordPress environment.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published