ZeroHour

CVE-2024-5071

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p34
Published
()
Modified
Description

The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.

Vendors
wpbookster
Products
bookster
Ecosystems
WordPress
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.