CVE-2024-12558: WP BASE Booking of Appointments, Services and Events <= 4.9.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via app_export_db
The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the exportdb function in all versions up to, and including, 4.9.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to expose sensitive information from the database, such as the hashed administrator password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12558?
CVE-2024-12558 has a high severity level due to the potential for unauthorized access to sensitive data.
How do I fix CVE-2024-12558?
To fix CVE-2024-12558, update the WP BASE Booking of Appointments, Services and Events plugin to version 5.0.0 or later.
Who is affected by CVE-2024-12558?
CVE-2024-12558 affects all versions of the WP BASE Booking of Appointments, Services and Events plugin up to and including version 4.9.2.
What type of attack can exploit CVE-2024-12558?
Authenticated attackers can exploit CVE-2024-12558 to access and export sensitive data due to the missing capability check.
Is CVE-2024-12558 under active exploitation?
There have been indications that CVE-2024-12558 is being actively exploited, making immediate remediation critical.