Access violation vulnerability in Booking Calendar | Appointment Booking | Bookit 2.5.0

The Booking Calendar | Appointment Booking | Bookit plugin for WordPress has a security issue that could allow unauthorized changes to be made to data. This is because the plugin does not have a check in place to verify user capabilities when using the ‘/wp-json/bookit/v1/commerce/stripe/return’ REST API Endpoint. This vulnerability exists in all versions up to and including 2.5.0. This means that individuals without proper authentication could potentially connect their Stripe account and receive payments without permission.

Detected in:

Booking Calendar | Appointment Booking | BookIt fixed vulnerable versions: >= * <= 2.5.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.