CVE-2024-2844: Easy Appointments <= 3.11.18 - Insufficient Authorization
The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient user validation on the ajaxcancelappointment() function in all versions up to, and including, 3.11.18. This makes it possible for unauthenticated attackers to cancel other users orders.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2844?
The severity of CVE-2024-2844 is considered high due to the potential for unauthorized data modification.
How do I fix CVE-2024-2844?
To fix CVE-2024-2844, update the Easy Appointments plugin to version 3.11.19 or later.
Who is affected by CVE-2024-2844?
CVE-2024-2844 affects all users of the Easy Appointments plugin for WordPress versions up to and including 3.11.18.
What type of attacks can be performed using CVE-2024-2844?
Exploiting CVE-2024-2844 allows unauthenticated attackers to cancel other users' appointments.
What functionality is affected by CVE-2024-2844?
The ajax_cancel_appointment() function is the main functionality affected by CVE-2024-2844.