Description
WordPress Plugin Appointment Booking Calendar and Online Scheduling-BookingPress is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently update arbitrary options on the site and upload arbitrary files. WordPress Plugin Appointment Booking Calendar and Online Scheduling-BookingPress version 1.1.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.6 or latest
References
Related Vulnerabilities
WordPress Plugin Haiku minimalist audio player Cross-Site Scripting (1.0.0)
PHP Other Vulnerability (CVE-2007-1376)
WordPress Plugin WP Social Feed Gallery Cross-Site Request Forgery (2.4.7)
Magento Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-7851)
WordPress Plugin Ultimate TinyMCE Multiple Unspecified Vulnerabilities (5.0)