Authentication vulnerability in Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress 1.1.7

The Appointment Booking Calendar and Online Scheduling Plugin for WordPress, called BookingPress, has a security issue in versions 1.1.6 to 1.1.7. This means that the plugin does not check a user’s identity before allowing them to log in after making a booking. This could allow unauthorized users to log in as registered users, even administrators, if they know the user’s email address. This only happens if the ‘Auto login user after successful booking’ option is turned on.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.