Record summary

CVE-2019-15774 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Aug 5, 2019 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMND Booking < 2.5 - Unauthenticated Options ChangeCVSS 6.1

The Hotel Booking WordPress plugin ND Booking < 2.5 was affected by an Unauthenticated Options Change security vulnerability.

Impact

Unauthenticated attackers can modify WordPress plugin options, potentially enabling development mode or altering plugin configuration to facilitate further attacks or compromise site functionality.

Remediation

Update the ND Booking plugin to version 2.5 or later.

WeaknessesCWE-601
Authorspopcorn94
Template tagscvecve2019wordpresswp-pluginnd-bookingintrusivevkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:booking_project:booking:*:*:*:*:*:wordpress:*:*
Shodan: http.html:"/wp-content/plugins/nd-booking"
FOFA: body="/wp-content/plugins/nd-booking/"

Source: ProjectDiscovery

References

4