CVE-2024-24715: WordPress WordPress BookIt Plugin plugin <= 2.4.0 - Price Bypass Vulnerability vulnerability
Improper Validation of Specified Quantity in Input vulnerability in The Events Calendar BookIt allows Manipulating Hidden Fields.This issue affects BookIt: from n/a through 2.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress BookIt plugin (The Events Calendar BookIt)to a version that resolves this vulnerability.Fixed in 2.4.2
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24715?
CVE-2024-24715 has a moderate severity rating due to its potential to allow manipulation of hidden fields in the BookIt plugin.
How do I fix CVE-2024-24715?
To fix CVE-2024-24715, update The Events Calendar BookIt plugin to a version later than 2.4.0.
What impact does CVE-2024-24715 have on my website?
CVE-2024-24715 can lead to unauthorized manipulation of booking data which may affect pricing and availability.
Is CVE-2024-24715 specific to certain versions of the BookIt plugin?
Yes, CVE-2024-24715 specifically affects The Events Calendar BookIt versions from n/a through 2.4.0.
Who is affected by CVE-2024-24715?
Users of The Events Calendar BookIt plugin and the associated WordPress plugin versions up to 2.4.0 are affected by CVE-2024-24715.