cleantalk
Vulnerabilities and Security Researches

BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin, CVE-2022-4340

CVE, Research URL

CVE-2022-4340

Published on
Jan 03, 2023
Research Description
The BookingPress WordPress plugin before 1.0.31 suffers from an Insecure Direct Object Reference (IDOR) vulnerability in it's thank you page, allowing any visitor to display information about any booking, including full name, date, time and service booked, by manipulating the appointment_id query parameter.
Affected versions
max 1.0.31.
Status
vulnerable