Description
WordPress Plugin Booking calendar, Appointment Booking System is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently manipulate the parameter values to change data such as prices. WordPress Plugin Booking calendar, Appointment Booking System version 2.2.2 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Membership Simplified Multiple SQL Injection Vulnerabilities (1.58)
WordPress Plugin WP Domain Redirect SQL Injection (1.0)
Drupal Core 4.5.x Multiple Vulnerabilities (4.5.0 - 4.5.5)
WordPress Plugin Advanced Dynamic Pricing for WooCommerce Multiple Vulnerabilities (4.1.5)
WordPress Plugin Download Monitor Unspecified Vulnerability (1.9.6)