First published: Wed Jun 13 2018(Updated: )
An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the values to change data such as prices.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wpdevart Booking Calendar | =2.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10363 refers to an issue discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress, where multiple parameters can be manipulated by remote attackers to change data such as prices.
CVE-2018-10363 has a severity rating of 7.5 (high).
The WpDevArt "Booking calendar, Appointment Booking System" plugin version 2.2.2 for WordPress is affected by CVE-2018-10363.
At the moment, no specific fix has been mentioned for CVE-2018-10363. It is recommended to stay updated with the latest version of the plugin and follow any instructions provided by the vendor.
More information about CVE-2018-10363 can be found at the following reference: https://gist.github.com/B0UG/68d3161af0c0ec85c615ca7452f9755e.