CVE-2024-5071

The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpbookster:bookster:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2024-06-26 06:15

Updated : 2025-05-19 21:02


NVD link : CVE-2024-5071

Mitre link : CVE-2024-5071

CVE.ORG link : CVE-2024-5071


JSON object : View

Products Affected

wpbookster

  • bookster
CWE
CWE-863

Incorrect Authorization