Описание
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.
EPSS
Процентиль: 35%
0.00412
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 6.5
github
26 дней назад
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.
EPSS
Процентиль: 35%
0.00412
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-287