Booking Package <= 1.5.98 - Authorization Bypass to Arbitrary Password Reset

2023-07-05 00:00
Rafie Muhammad

Strategic Overview

Status
Patched in 1.5.99
Affected PluginBooking Package
Affected Version< 1.5.99
CVSS9.8Critical
CVECVE-2023-37389
View all Booking Package vulnerabilities

Vulnerability Overview

The Booking Package plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including 1.5.98 due to missing validation in the 'updateUser' function. This allows unauthenticated attackers to reset the email and password of any user on the site if they know the username. Note that only sites that have an active premium subscription are vulnerable.

Technical Analysis

REMEDIATION: Update to version 1.5.99, or a newer patched version --- IDENTIFIER: CWE-639 (Authorization Bypass Through User-Controlled Key) The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C