Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-52p7-4rrr-jvcv

Опубликовано: 18 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment identified by a request-supplied id, allowing unauthenticated attackers to overwrite, and through a follow-on cleanup delete, arbitrary appointments.

The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment identified by a request-supplied id, allowing unauthenticated attackers to overwrite, and through a follow-on cleanup delete, arbitrary appointments.

EPSS

Процентиль: 13%
0.00221
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 5.3
nvd
6 дней назад

The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment identified by a request-supplied id, allowing unauthenticated attackers to overwrite, and through a follow-on cleanup delete, arbitrary appointments.

EPSS

Процентиль: 13%
0.00221
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-639