BookIt <=2.4.0 - Price Bypass

2024-01-31 00:00
Debangshu Kundu

Strategic Overview

Status
Patched in 2.4.1
Affected Version<= 2.4.0
CVSS4.9Medium
CVECVE-2024-24715
View all Bookit — Booking & Appointment Calendar vulnerabilities

Vulnerability Overview

The Booking Calendar | Appointment Booking | BookIt plugin for WordPress is vulnerable to Price Bypass in versions up to and including 2.4.0. This makes it possible for site owners to make use of premium plugin features without paying. Note that this does not meaningfully negatively impact site owners themselves.

Technical Analysis

REMEDIATION: Update to version 2.4.1, or a newer patched version --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C