WP Booking Calendar <= 10.10 - Unauthenticated Post-Confirmation Booking Manipulation
Vulnerability Description
The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and including, 10.10. This is due to the plugin not properly requiring re-verification after a booking has been made and a change is being attempted. This makes it possible for unauthenticated attackers to manipulate their confirmed bookings, even after they have been approved.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-13821
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Asaf Mozes
References
More from wpdevelop
View All →Affected Vendor
wpdevelop
View all reports →