First published: Mon Dec 09 2024(Updated: )
Missing Authorization vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WpDevArt Booking Calendar | <=3.2.3 | |
WordPress Booking Calendar | <=3.2.3 |
Update the WordPress Booking calendar, Appointment Booking System plugin to the latest available version (at least 3.2.4).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24407 is considered a critical severity vulnerability due to its potential for unauthorized access.
To fix CVE-2023-24407, update the WpDevArt Booking calendar, Appointment Booking System to version 3.2.4 or later.
The potential impacts of CVE-2023-24407 include unauthorized access to user bookings and sensitive information.
CVE-2023-24407 affects the WpDevArt Booking calendar, Appointment Booking System versions up to and including 3.2.3.
CVE-2023-24407 is classified as a Missing Authorization vulnerability, indicating improper access control.