Description
WordPress Plugin Appointment Booking Calendar and Online Scheduling-BookingPress is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently update arbitrary options on the site and upload arbitrary files. WordPress Plugin Appointment Booking Calendar and Online Scheduling-BookingPress version 1.1.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.6 or latest
References
Related Vulnerabilities
Plone CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2012-5485)
silverstripeCMS Improper Restriction of XML External Entity Reference Vulnerability (CVE-2020-25817)
Python Improper Encoding or Escaping of Output Vulnerability (CVE-2026-6019)
WordPress Plugin Feed Them Gallery Cross-Site Scripting (1.1.8)