First published: Mon Dec 09 2024(Updated: )
Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Time Slots Booking Form: from n/a through 1.1.82.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
CodePeople WP Time Slots Booking Form | <=1.1.82 | |
CodePeople WP Time Slots Booking Form | <=1.1.82 | |
<1.1.83 |
Update the WordPress WP Time Slots Booking Form plugin to the latest available version (at least 1.1.83).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23895 is classified as a missing authorization vulnerability that affects the CodePeople WP Time Slots Booking Form.
To fix CVE-2023-23895, update the CodePeople WP Time Slots Booking Form to version 1.1.83 or later.
CVE-2023-23895 affects all versions of the WP Time Slots Booking Form up to and including version 1.1.82.
Attackers exploiting CVE-2023-23895 can potentially gain unauthorized access due to incorrectly configured access control levels.
Yes, CVE-2023-23895 is particularly vulnerable if the access control settings are misconfigured in the WP Time Slots Booking Form.