CVE-2023-38520 MEDIUM

CVE-2023-38520: WordPress Pinpoint Booking System plugin <= 2.9.9.3.4 - Parameter Tampering

Vendor Pinpoint.world
Product Pinpoint Booking System
Weakness CWE-472
Published June 4, 2024
Last update April 28, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

External Control of Assumed-Immutable Web Parameter vulnerability in PINPOINT.WORLD Pinpoint Booking System allows Functionality Misuse.This issue affects Pinpoint Booking System: from n/a through 2.9.9.3.4.

Explanation of Vulnerability in Simple Terms

02Summary

Pinpoint Booking System versions up to 2.9.9.3.4 contain a vulnerability that allows an attacker to modify data or disrupt service availability. The vulnerability requires no authentication or user interaction and can be exploited over the network. No confidentiality impact has been identified, but integrity and availability of the system are at risk.

What an attacker can do

03Attacker Capabilities

Modify booking data or cause the system to become unavailable without authentication.

Potential impact on your site

04Site Impact

Bookings may be altered or deleted, and the booking system may become unavailable to legitimate users.

Conditions required to exploit

05Prerequisites

Network access to the Pinpoint Booking System; no authentication or user interaction required.

Key dates

06Disclosure timeline

June 4, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE