Headline
CVE-2022-41692: WordPress Appointment Hour Booking plugin <= 1.3.71 - Missing Authorization vulnerability - Patchstack
Missing Authorization vulnerability in Appointment Hour Booking plugin <= 1.3.71 on WordPress.
Verified
Fixed
4.3
CVSS 3.1 score Medium severity
Report
Monitoring Not reported to be exploited
Vulnerable versions
<= 1.3.71
PSID
6361a286ba40
Classification
Other Vulnerability Type
OWASP Top 10
A5: Broken Access Control
Required privilege
Requires subscriber or higher role user authentication.
Publicly disclosed
2022-10-30
Details
Missing Authorization vulnerability leading to Feedback Submission discovered by Lana Codes (Patchstack Alliance) in the WordPress Appointment Hour Booking plugin (versions <= 1.3.71).
Solution
Update the WordPress Appointment Hour Booking plugin to the latest available version (at least 1.3.72).
References