CVE-2024-4468: Salon booking system <= 9.9 - Missing Authorization
The Salon booking system plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions hooked into admininit in all versions up to, and including, 9.9. This makes it possible for authenticated attackers with subscriber access or higher to modify plugin settings and view discount codes intended for other users.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Salon booking system pluginto a version that resolves this vulnerability.Fixed in 9.9 - Compensating control
Restrict access to WordPress admin_init-triggered plugin admin endpoints to users with appropriate capabilities (since the vulnerability is a missing capability check affecting authenticated users with subscriber access or higher).
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4468?
CVE-2024-4468 is classified as a high severity vulnerability due to its potential for unauthorized access and data modification.
How do I fix CVE-2024-4468?
To fix CVE-2024-4468, upgrade the Salon Booking System plugin to version 10.0 or later.
Who is affected by CVE-2024-4468?
All versions of the Salon Booking System plugin for WordPress up to and including 9.9 are affected by CVE-2024-4468.
What actions can an attacker perform due to CVE-2024-4468?
An attacker can gain unauthorized access and modify data in the Salon Booking System plugin due to a missing capability check.
When was CVE-2024-4468 disclosed?
CVE-2024-4468 was disclosed recently, with organizations encouraged to address it promptly to prevent exploitation.