What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 1.15.78.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 1.15.78.
Explanation of Vulnerability in Simple Terms
WooCommerce Bookings versions up to 1.15.78 contain an authorization flaw that allows authenticated users with low privileges to modify booking data and disrupt service availability. The vulnerability does not expose sensitive information but can corrupt booking records or prevent legitimate bookings from being processed. Site owners should update to a version newer than 1.15.78.
What an attacker can do
Modify booking records or cause booking system disruption with a low-privilege account.
Potential impact on your site
Booking data integrity compromised; legitimate bookings may fail or be altered by unauthorized users.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the site.
Key dates
External resources
Related vulnerabilities