BookIt <=2.4.0 - Price Bypass
2024-01-31 00:00
Debangshu KunduStrategic Overview
StatusPatched in 2.4.1
Affected PluginBookit — Booking & Appointment Calendar
Affected Version
<= 2.4.0CVSS4.9Medium
CVE
CVE-2024-24715Vulnerability Overview
The Booking Calendar | Appointment Booking | BookIt plugin for WordPress is vulnerable to Price Bypass in versions up to and including 2.4.0. This makes it possible for site owners to make use of premium plugin features without paying. Note that this does not meaningfully negatively impact site owners themselves.
Technical Analysis
REMEDIATION: Update to version 2.4.1, or a newer patched version --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C