Description
WordPress Plugin Appointment Booking Calendar and Online Scheduling-BookingPress is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently update arbitrary options on the site and upload arbitrary files. WordPress Plugin Appointment Booking Calendar and Online Scheduling-BookingPress version 1.1.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.6 or latest
References
Related Vulnerabilities
WordPress Plugin Display Users SQL Injection (2.0.0)
WordPress Plugin HTML5 Video Player-Best WordPress Video Player and Block SQL Injection (2.5.26)
AngularJS Inefficient Regular Expression Complexity Vulnerability (CVE-2023-26117)
MediaWiki Other Vulnerability (CVE-2020-27621)
WordPress Plugin Google Alert And Twitter Multiple Vulnerabilities (3.1.5)