The BookingPress WordPress plugin before 1.0.31 suffers from an Insecure Direct Object Reference (IDOR) vulnerability in it's thank you page, allowing any visitor to display information about any booking, including full name, date, time and service booked, by manipulating the appointment_id query parameter.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2023-01-02T21:49:16.234Z
Updated: 2024-08-03T01:34:50.175Z
Reserved: 2022-12-07T18:55:53.164Z
Link: CVE-2022-4340
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-01-02T22:15:17.127
Modified: 2024-11-21T07:35:05.203
Link: CVE-2022-4340
Redhat
No data.