Booking Package <= 1.5.98 - Authorization Bypass to Arbitrary Password Reset
Strategic Overview
< 1.5.99CVE-2023-37389Vulnerability Overview
The Booking Package plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including 1.5.98 due to missing validation in the 'updateUser' function. This allows unauthenticated attackers to reset the email and password of any user on the site if they know the username. Note that only sites that have an active premium subscription are vulnerable.
Technical Analysis
REMEDIATION: Update to version 1.5.99, or a newer patched version --- IDENTIFIER: CWE-639 (Authorization Bypass Through User-Controlled Key) The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C