CVE-2024-13821

The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and including, 10.10. This is due to the plugin not properly requiring re-verification after a booking has been made and a change is being attempted. This makes it possible for unauthenticated attackers to manipulate their confirmed bookings, even after they have been approved.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpbookingcalendar:booking_calendar:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2025-02-12 08:15

Updated : 2025-02-25 19:37


NVD link : CVE-2024-13821

Mitre link : CVE-2024-13821

CVE.ORG link : CVE-2024-13821


JSON object : View

Products Affected

wpbookingcalendar

  • booking_calendar
CWE
CWE-285

Improper Authorization

NVD-CWE-noinfo