CVE-2023-24373: WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Bypass vulnerability
External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Manipulating Hidden Fields.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24373?
CVE-2023-24373 is considered a high severity vulnerability due to its potential for manipulating hidden fields.
How do I fix CVE-2023-24373?
To fix CVE-2023-24373, upgrade the WpDevArt Booking calendar, Appointment Booking System to version 3.2.4 or later.
What types of software are affected by CVE-2023-24373?
CVE-2023-24373 affects versions of WpDevArt Booking calendar, Appointment Booking System up to 3.2.3.
What kind of attack does CVE-2023-24373 enable?
CVE-2023-24373 enables attackers to manipulate hidden fields, which may lead to unauthorized changes in booking data.
Is CVE-2023-24373 specific to WordPress?
Yes, CVE-2023-24373 specifically affects the WordPress Booking calendar, Appointment Booking System plugin.