CVE-2024-31296: WordPress BookingPress plugin <= 1.0.81 - Insecure Direct Object References (IDOR) vulnerability
Published Apr 7, 2024
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in Repute Infosystems BookingPress.This issue affects BookingPress: from n/a through 1.0.81.
Affected Software
3 affected components
Repute Infosystems BookingPress<=1.0.81
WordPress BookingPress<=1.0.81
reputeinfosystems Bookingpress Wordpress<1.0.82
Remediation
Information
Update to 1.0.82 or a higher version.
Event History
Apr 7, 2024
CVE Published
via MITRE·06:07 PM
Data Sourced
via MITRE·06:07 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-31296?
CVE-2024-31296 has been classified as a critical severity vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2024-31296?
To mitigate CVE-2024-31296, update BookingPress to a version higher than 1.0.81 or apply relevant security patches.
3
What systems are affected by CVE-2024-31296?
CVE-2024-31296 affects Repute Infosystems BookingPress versions up to 1.0.81.
4
Can CVE-2024-31296 be exploited remotely?
Yes, CVE-2024-31296 can be exploited remotely if the attacker has network access to the affected BookingPress installations.
5
Is there a workaround for CVE-2024-31296?
Currently, the best workaround for CVE-2024-31296 is to restrict access to the BookingPress plugin until it can be updated.