Record summary

CVE-2022-2373 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Simply Schedule Appointments – WordPress Booking Plugin

CVE List1.5.7.7 to < 1.5.7.7affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Simply Schedule Appointments <1.5.7.7 - Information DisclosureCVSS 5.3

WordPress Simply Schedule Appointments plugin before 1.5.7.7 is susceptible to information disclosure. The plugin is missing authorization in a REST endpoint, which can allow an attacker to retrieve user details such as name and email address.

Impact

An attacker can exploit this vulnerability to gain sensitive information from the target system.

Remediation

Update to the latest version of the Simply Schedule Appointments plugin (1.5.7.7 or higher) to fix the information disclosure vulnerability.

WeaknessesCWE-862
Authorstheamanrawat, theabhinavgaur
Template tagscvecve2022simply-schedule-appointmentsunauthwpscanwordpresswp-pluginwpnsquavuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:nsqua:simply_schedule_appointments:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2