PT-2025-1798 · WordPress · Appointment Booking Calendar Plugin
Published
2025-01-13
·
Updated
2025-05-08
·
CVE-2024-12274
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Appointment Booking Calendar Plugin and Scheduling Plugin versions prior to 1.1.23
Description
The export settings functionality in the Appointment Booking Calendar Plugin and Scheduling Plugin exports data to a public folder with an easily guessable file name, allowing unauthenticated attackers to access the exported files if they exist. This issue can be exploited by accessing the easily guessable file name in the public folder where the exported files are stored.
Recommendations
For versions prior to 1.1.23, update to version 1.1.23 or later to resolve the issue. As a temporary workaround, consider restricting access to the public folder where the exported files are stored to minimize the risk of exploitation. Avoid using the export settings functionality until the issue is resolved.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Appointment Booking Calendar Plugin