WordPress 插件 Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin 在所有 1.6.11.11 及更低版本中存在不正确的授权漏洞。该漏洞源于预约更新的 REST API 端点未限制经令牌认证的客户可修改的字段。攻击者无需身份验证即可修改该预约中由管理员控制的字段,包括伪造付款确认、将预约重新分配给其他用户以及更改服务类型。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| croixhaug | Simply Schedule Appointments | 0 ~ 1.6.11.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet