CVE-2023-24407: WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Broken Access Control vulnerability
Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24407?
CVE-2023-24407 is considered a critical severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2023-24407?
To fix CVE-2023-24407, update the WpDevArt Booking calendar, Appointment Booking System to version 3.2.4 or later.
What are the potential impacts of CVE-2023-24407?
The potential impacts of CVE-2023-24407 include unauthorized access to user bookings and sensitive information.
Which versions of the Booking calendar, Appointment Booking System are affected by CVE-2023-24407?
CVE-2023-24407 affects the WpDevArt Booking calendar, Appointment Booking System versions up to and including 3.2.3.
What type of vulnerability is CVE-2023-24407 classified as?
CVE-2023-24407 is classified as a Missing Authorization vulnerability, indicating improper access control.