The BookingPress WordPress plugin before 1.0.31 suffers from an Insecure Direct Object Reference (IDOR) vulnerability in it's thank you page, allowing any visitor to display information about any booking, including full name, date, time and service booked, by manipulating the appointment_id query parameter.
Metrics
Affected Vendors & Products
References
History
Thu, 10 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published: 2023-01-02T21:49:16.234Z
Updated: 2025-04-10T19:06:17.234Z
Reserved: 2022-12-07T18:55:53.164Z
Link: CVE-2022-4340
Updated: 2024-08-03T01:34:50.175Z
Status : Modified
Published: 2023-01-02T22:15:17.127
Modified: 2025-04-10T19:15:53.030
Link: CVE-2022-4340
No data.