The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and including, 10.10. This is due to the plugin not properly requiring re-verification after a booking has been made and a change is being attempted. This makes it possible for unauthenticated attackers to manipulate their confirmed bookings, even after they have been approved.
CVSS
No CVSS.
References
Configurations
History
25 Feb 2025, 19:37
Type | Values Removed | Values Added |
---|---|---|
First Time |
Wpbookingcalendar booking Calendar
Wpbookingcalendar |
|
CPE | cpe:2.3:a:wpbookingcalendar:booking_calendar:*:*:*:*:*:wordpress:*:* | |
CWE | NVD-CWE-noinfo | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/8a0b961e-ccc3-4da0-b007-bbafa133a3a8?source=cve - Third Party Advisory | |
References | () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3234469%40booking&new=3234469%40booking&sfp_email=&sfph_mail=#file20 - Patch |
12 Feb 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : unknown |
12 Feb 2025, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-12 08:15
Updated : 2025-02-25 19:37
NVD link : CVE-2024-13821
Mitre link : CVE-2024-13821
JSON object : View
Products Affected
wpbookingcalendar
- booking_calendar
CWE