Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.2 - Missing Authorization on REST-API
2023-06-02 00:00
Jonas HöbenreichStrategic Overview
StatusPatched in 4.4.3
Affected PluginOnline Booking & Scheduling Calendar for WordPress by vcita
Affected Version
<= 4.4.2CVSS5.3Medium
CVE
CVE-2023-2299Vulnerability Overview
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized medication of data via the /wp-json/vcita-wordpress/v1/actions/auth REST-API endpoint in versions up to, and including, 4.4.2 due to a missing capability check on the processAction function. This makes it possible for unauthenticated attackers modify the plugin's settings.
Technical Analysis
REMEDIATION: Update to version 4.4.3, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C