CVE-2022-2373
Simply Schedule Appointments < 1.5.7.7 - Unauthenticated Email Address Disclosure
Record summary
CVE-2022-2373 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Simply Schedule Appointments – WordPress Booking Plugin | CVE List | 1.5.7.7 to < 1.5.7.7 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Simply Schedule Appointments <1.5.7.7 - Information DisclosureCVSS 5.3
WordPress Simply Schedule Appointments plugin before 1.5.7.7 is susceptible to information disclosure. The plugin is missing authorization in a REST endpoint, which can allow an attacker to retrieve user details such as name and email address.
Impact
An attacker can exploit this vulnerability to gain sensitive information from the target system.
Remediation
Update to the latest version of the Simply Schedule Appointments plugin (1.5.7.7 or higher) to fix the information disclosure vulnerability.
Source: ProjectDiscovery