The BookingPress WordPress plugin before 1.0.31 suffers from an Insecure Direct Object Reference (IDOR) vulnerability in it's thank you page, allowing any visitor to display information about any booking, including full name, date, time and service booked, by manipulating the appointment_id query parameter.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: WPScan
Published: 2023-01-02T21:49:16.234Z
Updated: 2024-08-03T01:34:50.175Z
Reserved: 2022-12-07T18:55:53.164Z
Link: CVE-2022-4340

No data.

Status : Modified
Published: 2023-01-02T22:15:17.127
Modified: 2024-11-21T07:35:05.203
Link: CVE-2022-4340

No data.