CVE-2024-24715: WordPress WordPress BookIt Plugin plugin <= 2.4.0 - Price Bypass Vulnerability vulnerability
Published May 17, 2024
·Updated
Improper Validation of Specified Quantity in Input vulnerability in The Events Calendar BookIt allows Manipulating Hidden Fields.This issue affects BookIt: from n/a through 2.4.0.
Affected Software
2 affected components
The Events Calendar BookIt>n/a, <=2.4.0
WordPress BookIt Plugin<=2.4.0
Remediation
Information
Update to 2.4.2 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·08:48 AM
Data Sourced
via MITRE·08:48 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-24715?
CVE-2024-24715 has a moderate severity rating due to its potential to allow manipulation of hidden fields in the BookIt plugin.
2
How do I fix CVE-2024-24715?
To fix CVE-2024-24715, update The Events Calendar BookIt plugin to a version later than 2.4.0.
3
What impact does CVE-2024-24715 have on my website?
CVE-2024-24715 can lead to unauthorized manipulation of booking data which may affect pricing and availability.
4
Is CVE-2024-24715 specific to certain versions of the BookIt plugin?
Yes, CVE-2024-24715 specifically affects The Events Calendar BookIt versions from n/a through 2.4.0.
5
Who is affected by CVE-2024-24715?
Users of The Events Calendar BookIt plugin and the associated WordPress plugin versions up to 2.4.0 are affected by CVE-2024-24715.