CVE-2024-34799: WordPress BookingPress plugin <= 1.0.82 - Appointment Duration Manipulation vulnerability
Published Jun 11, 2024
·Updated
Missing Authorization vulnerability in Repute Infosystems BookingPress.This issue affects BookingPress: from n/a through 1.0.82.
Affected Software
3 affected components
Repute Infosystems BookingPress<=1.0.82
WordPress BookingPress<=1.0.82
reputeinfosystems Bookingpress Wordpress<1.0.83
Remediation
Information
Update to 1.0.83 or a higher version.
Event History
Jun 11, 2024
CVE Published
via MITRE·04:35 PM
Data Sourced
via MITRE·04:35 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-34799?
CVE-2024-34799 is categorized as a missing authorization vulnerability which can lead to unauthorized access.
2
How do I fix CVE-2024-34799?
To fix CVE-2024-34799, update BookingPress to the latest version beyond 1.0.82 immediately.
3
Who is affected by CVE-2024-34799?
CVE-2024-34799 affects all versions of BookingPress from n/a through 1.0.82.
4
What implications does CVE-2024-34799 have for BookingPress users?
CVE-2024-34799 can allow attackers to access functionalities without proper authorization, posing a security risk.
5
Is there a patch available for CVE-2024-34799?
Yes, a patch is available by updating BookingPress to a version higher than 1.0.82.