The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_db function in all versions up to, and including, 4.9.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to expose sensitive information from the database, such as the hashed administrator password.
Metrics
Affected Vendors & Products
References
History
Sat, 21 Dec 2024 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_db function in all versions up to, and including, 4.9.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to expose sensitive information from the database, such as the hashed administrator password. | |
Title | WP BASE Booking of Appointments, Services and Events <= 4.9.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via app_export_db | |
Weaknesses | CWE-862 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-12-21T09:23:54.011Z
Updated: 2024-12-21T09:23:54.011Z
Reserved: 2024-12-11T23:23:55.808Z
Link: CVE-2024-12558
Vulnrichment
No data.
NVD
Status : Received
Published: 2024-12-21T10:15:08.600
Modified: 2024-12-21T10:15:08.600
Link: CVE-2024-12558
Redhat
No data.