Description
WordPress Plugin Booking calendar, Appointment Booking System is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently manipulate the parameter values to change data such as prices. WordPress Plugin Booking calendar, Appointment Booking System version 2.2.2 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin WP Statistics Multiple Cross-Site Scripting Vulnerabilities (2.2.4)
WordPress Plugin TableOn-WordPress Posts Table Filterable Cross-Site Scripting (1.0.0)
WordPress Plugin WP Inimat Cross-Site Scripting (1.0)
Play Framework Uncontrolled Resource Consumption Vulnerability (CVE-2022-31018)
WordPress Plugin Download Monitor Cross-Site Scripting (1.7.0)