WF-12d7a152-90cd-4c92-90c4-81c594e6c9ac
Booking Ultra Pro Appointments Booking Calendar Plugin に報告された脆弱性
高深刻度
8.8CVSS
1.1.6修正されたバージョン
—30日以内に悪用される確率
概要
The Booking Ultra Pro plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on most AJAX actions in versions up to, and including, 1.1.5. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update user profiles, change opening hours and modify a variety of other settings.
影響を受けるバージョン
- 1.1.5 以下
対処方法
Booking Ultra Pro Appointments Booking Calendar Plugin を 1.1.6 以降に更新してください。これで本脆弱性は解消します。
Booking Ultra Pro Appointments Booking Calendar Plugin の他の脆弱性を見る →
あなたのサイトは大丈夫ですか?
URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。
30秒で無料診断する