First published: Fri Mar 29 2024(Updated: )
The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient user validation on the ajax_cancel_appointment() function in all versions up to, and including, 3.11.18. This makes it possible for unauthenticated attackers to cancel other users orders.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Easy Appointments | <3.11.19 | |
Easy Appointments | <=3.11.18 | |
WordPress |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-2844 is considered high due to the potential for unauthorized data modification.
To fix CVE-2024-2844, update the Easy Appointments plugin to version 3.11.19 or later.
CVE-2024-2844 affects all users of the Easy Appointments plugin for WordPress versions up to and including 3.11.18.
Exploiting CVE-2024-2844 allows unauthenticated attackers to cancel other users' appointments.
The ajax_cancel_appointment() function is the main functionality affected by CVE-2024-2844.