The BookingPress WordPress plugin before 1.0.31 suffers from an Insecure Direct Object Reference (IDOR) vulnerability in it's thank you page, allowing any visitor to display information about any booking, including full name, date, time and service booked, by manipulating the appointment_id query parameter.
Metrics
Affected Vendors & Products
References
History
Thu, 10 Apr 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-10T19:06:17.234Z
Reserved: 2022-12-07T18:55:53.164Z
Link: CVE-2022-4340

Updated: 2024-08-03T01:34:50.175Z

Status : Modified
Published: 2023-01-02T22:15:17.127
Modified: 2025-04-10T19:15:53.030
Link: CVE-2022-4340

No data.