What the vulnerability does
01Description
Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.1.76.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.1.76.
Explanation of Vulnerability in Simple Terms
WP Time Slots Booking Form through version 1.1.76 fails to properly check user permissions before allowing modifications to booking data. A logged-in user with low privileges can alter bookings they should not have access to. The vulnerability requires an active user account but no special interaction from victims.
What an attacker can do
Modify booking records belonging to other users or administrators.
Potential impact on your site
Booking data integrity is compromised; users' reservations can be altered by unauthorized accounts.
Conditions required to exploit
Attacker must have a low-privilege user account on the WordPress site.
Key dates
External resources
Related vulnerabilities