PT-2023-32336 · WordPress · Wp Hotel Booking

·

CVE-2023-5799

·

Publicado

2023-11-20

·

Atualizado

2023-11-27

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions WP Hotel Booking WordPress plugin versions prior to 2.0.8
Description The issue concerns a lack of proper authorization in the deletion of packages. This allows users with Contributor and above roles to delete posts that do not belong to them.
Recommendations For versions prior to 2.0.8, update to version 2.0.8 or later to resolve the issue.

Exploit

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-5799

Produtos afetados

Wp Hotel Booking