VulnerabilityModified
CVE-2023-1129
The WP FEvents Book WordPress plugin through 0.46 does not ensures that bookings to be updated belong to the user making the request, allowing any authenticated user to book, add notes, or cancel booking on behalf of other users.
MEDIUM 6.5EPSS 0.56%
Does this matter?
Lower severity and a low EPSS score (0.56%). Track it; it rarely justifies an emergency change on its own.
Description
The WP FEvents Book WordPress plugin through 0.46 does not ensures that bookings to be updated belong to the user making the request, allowing any authenticated user to book, add notes, or cancel booking on behalf of other users.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Affected
- wp fevents book project/wp fevents book
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/d40479de-fb04-41b8-9fb0-41b9eefbd8afExploit, Third Party Advisory
- https://wpscan.com/vulnerability/d40479de-fb04-41b8-9fb0-41b9eefbd8afExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.