Back

MEDIUM

Bookster <= 1.1.0 - Unauthenticated Appointment Status Update

Published Jun 26, 2024

Description

The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Jun 26, 2024
Updated Oct 28, 2024
Reserved May 17, 2024
CISA Vulnrichment
Updated Jun 26, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner WPScan
Published Jun 26, 2024
Updated Oct 28, 2024
Exploited since n/a
EUVD-2024-46332