Description
An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the values to change data such as prices.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_misc
https://gist.github.com/B0UG/68d3161af0c0ec85c615ca7452f9755e
Scores
CVSS v3
7.5
EPSS
0.0137
EPSS Percentile
68.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-20
Status
published
Products (1)
wpdevart/booking_calendar
2.2.2
Published
Jun 13, 2018
Tracked Since
Feb 18, 2026