What the vulnerability does
01Description
Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.2.06.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
What the vulnerability does
Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.2.06.
Explanation of Vulnerability in Simple Terms
WP Time Slots Booking Form through version 1.2.06 lacks proper authorization checks, allowing unauthenticated attackers to modify booking data. An attacker can send network requests to alter or delete time slot bookings without needing to log in or interact with a user. Site owners using this plugin should update immediately to prevent unauthorized changes to their booking system.
What an attacker can do
Modify or delete time slot bookings without logging in.
Potential impact on your site
Booking data can be altered or deleted by anyone, disrupting your scheduling system and customer trust.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities