ZeroHour

CVE-2023-1129

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p45
Published
()
Modified
Description

The WP FEvents Book WordPress plugin through 0.46 does not ensures that bookings to be updated belong to the user making the request, allowing any authenticated user to book, add notes, or cancel booking on behalf of other users.

Vendors
wp fevents book project
Products
wp fevents book
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.