Back to search
CVE-2022-2373
Published: Aug 29, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address
| Vendor | Product | Versions |
|---|---|---|
Unknown | Simply Schedule Appointments – WordPress Booking Plugin | affected 1.5.7.7 - < 1.5.7.7 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now