The BookingPress WordPress plugin before 1.0.31 suffers from an Insecure Direct Object Reference (IDOR) vulnerability in it's thank you page, allowing any visitor to display information about any booking, including full name, date, time and service booked, by manipulating the appointment_id query parameter.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2023-01-02T21:49:16.234Z

Updated: 2023-01-10T09:08:27.832Z

Reserved: 2022-12-07T18:55:53.164Z


Link: CVE-2022-4340

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-01-02T22:15:17.127

Modified: 2023-11-07T03:57:34.983


Link: CVE-2022-4340

JSON object: View

cve-icon Redhat Information

No data.

CWE

No CWE.