CVE Database
/

CVE-2022-4340

Back to search

CVE-2022-4340

Published: Jan 2, 2023

Modified: Apr 10, 2025

PUBLISHED

Description

The BookingPress WordPress plugin before 1.0.31 suffers from an Insecure Direct Object Reference (IDOR) vulnerability in it's thank you page, allowing any visitor to display information about any booking, including full name, date, time and service booked, by manipulating the appointment_id query parameter.

VendorProductVersions

Unknown

BookingPress

affected
0 - < 1.0.31

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now