The Bookster WordPress plugin through 1.1.0 allows...
Moderate severity
Unreviewed
Published
Jun 26, 2024
to the GitHub Advisory Database
•
Updated Oct 29, 2024
Description
Published by the National Vulnerability Database
Jun 26, 2024
Published to the GitHub Advisory Database
Jun 26, 2024
Last updated
Oct 29, 2024
The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.
References