CVE-2024-5071

MEDIUM

Bookster < 1.1.0 - Incorrect Authorization via Appointment Status Manipulation

Title source: llm
STIX 2.1

Description

The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/07b293cf-5174-45de-8606-a782a96a35b3/

Scores

CVSS v3 6.5
EPSS 0.0040
EPSS Percentile 31.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
wpbookster/bookster < 1.1.0
Published Jun 26, 2024
Tracked Since Feb 18, 2026