CVE-2024-10215: WPBookit <= 1.6.4 - Unauthenticated Arbitrary User Password Change
The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10215?
CVE-2024-10215 is rated as a high severity vulnerability due to its potential for unauthorized password changes.
How do I fix CVE-2024-10215?
To fix CVE-2024-10215, update the WPBookit plugin to version 1.6.5 or later immediately.
What are the consequences of not addressing CVE-2024-10215?
Failure to address CVE-2024-10215 could allow attackers to change user passwords and gain unauthorized access to accounts.
Which versions of WPBookit are affected by CVE-2024-10215?
CVE-2024-10215 affects all versions of WPBookit up to and including 1.6.4.
What type of vulnerability is CVE-2024-10215?
CVE-2024-10215 is classified as an arbitrary user password change vulnerability.