WordPress Plugin BookingPress-Appointments Booking Calendar and Online Scheduling Insecure Direct Object Reference - CVE-2022-4340 - Vulnerability Database

WordPress Plugin BookingPress-Appointments Booking Calendar and Online Scheduling Insecure Direct Object Reference - CVE-2022-4340

Medium
Reference: CVE-2022-4340
Title: WordPress Plugin BookingPress-Appointments Booking Calendar and Online Scheduling Insecure Direct Object Reference
Overview:

WordPress Plugin BookingPress-Appointments Booking Calendar and Online Scheduling is prone to a insecure direct object reference (IDOR) vulnerability. Exploiting this issue may allow an attacker to view information about any booking including full name date time and service booked. WordPress Plugin BookingPress-Appointments Booking Calendar and Online Scheduling version 1.0.30 is vulnerable prior versions may also be affected.