Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-85vh-crr4-c67p

Опубликовано: 12 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed bookings at an arbitrary price and to bypass the site's configured payment-method restrictions.

The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed bookings at an arbitrary price and to bypass the site's configured payment-method restrictions.

EPSS

Процентиль: 11%
0.00203
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 5.3
nvd
12 дней назад

The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed bookings at an arbitrary price and to bypass the site's configured payment-method restrictions.

EPSS

Процентиль: 11%
0.00203
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284