WP FEvents Book [wp-fevents-book] < 0.47 (closed)
unknown
[en] The WP FEvents Book WordPress plugin through 0.46 does not ensures that bookings to be updated belong to the user making the request, allowing any authenticated user to book, add notes, or cancel booking on behalf of other users.
- Affected:
- up to 0.47
- Fixed in:
- 0.47
- Disclosed:
- Apr 24, 2023
CVE-2023-1129 on NVD →
WP FEvents Book [wp-fevents-book] <= 0.46 (unfixed + closed)
unknown
[en] The WP FEvents Book WordPress plugin through 0.46 does not sanitise and escape some parameters, which could allow any authenticated users, such as subscriber to perform Cross-Site Scripting attacks
- Affected:
- up to 0.46
- Fix:
- No patched version reported
- Disclosed:
- Apr 24, 2023
CVE-2023-1126 on NVD →
WP FEvents Book <= 0.46 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The WP FEvents Book plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 0.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject arbit...
- CVSS:
- 6.4
- Affected:
- up to 0.46
- Fix:
- No patched version reported
- Disclosed:
- Apr 3, 2023
CVE-2023-1126 on NVD →
WP FEvents Book <= 0.46 - Authenticated (Subscriber+) Insecure Direct Object Reference to Booking Manipulation
medium
The WP FEvents Book plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to insufficient controls on the userID controlled via the showform_fevent6 function in versions up to, and including, 0.46. This makes it possible for authenticated attackers, with minimal p...
- CVSS:
- 6.3
- Affected:
- up to 0.46
- Fixed in:
- 0.47
- Disclosed:
- Apr 3, 2023
CVE-2023-1129 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database