PT-2025-6593 · WordPress · Getbookingswp

Hoang Phuc Vo

+1

·

Published

2025-02-18

·

Updated

2025-03-03

·

CVE-2024-13677

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GetBookingsWP – Appointments Booking Calendar Plugin For WordPress versions up to 1.1.27
Description The issue arises from the plugin's failure to properly validate a user's identity before updating their details, such as email addresses. This allows authenticated attackers with subscriber-level access or higher to change arbitrary users' email addresses, including those of administrators. The attackers can then leverage this capability to reset the user's password and gain access to their account.
Recommendations For versions up to 1.1.27, update the plugin to a version higher than 1.1.27 to resolve the issue. As a temporary workaround, consider restricting access to the plugin's user management features to minimize the risk of exploitation. Additionally, monitor user account activity for any suspicious changes to email addresses or password resets.

Fix

LPE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-13677

Affected Products

Getbookingswp