WordPress Plugin Vulnerabilities
BookingPress < 1.0.75 - Unauthenticated Booking Price Manipulation
Description
The plugin does not have proper validation in its bookingpress_confirm_booking, allowing unauthenticated user to modify the price of an appointment
Affects Plugins
References
Miscellaneous
Original Researcher
Abdi Pranata
Verified
No
WPVDB ID
Timeline
Publicly Published
2024-01-27 (about 2 years ago)
Added
2024-01-05 (about 2 years ago)
Last Updated
2024-01-05 (about 2 years ago)