CVE-2024-32720: WordPress Appointment Hour Booking plugin <= 1.4.56 - Captcha Bypass vulnerability
Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Appointment Hour Booking allows Removing Important Client Functionality.This issue affects Appointment Hour Booking: from n/a through 1.4.56.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32720?
CVE-2024-32720 is classified as a high severity vulnerability due to its potential to compromise client functionality.
How does CVE-2024-32720 affect users of Appointment Hour Booking?
CVE-2024-32720 allows attackers to bypass authentication attempts, leading to the removal of critical client functionality.
What versions of Appointment Hour Booking are affected by CVE-2024-32720?
The vulnerable versions are from n/a through 1.4.56 of Appointment Hour Booking.
How do I fix CVE-2024-32720?
To mitigate CVE-2024-32720, upgrade your Appointment Hour Booking plugin to a version beyond 1.4.56.
Is there a workaround for CVE-2024-32720 until I can update?
Currently, the best approach is to restrict access to the plugin settings while you plan for an upgrade.