PT-2026-60724 · WordPress · Wps Bookings For Woocommerce
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
WPS Bookings for WooCommerce WordPress plugin versions prior to 3.11.7
Description
The plugin fails to verify if a booking order belongs to the user making the request before processing a cancellation. This allows any authenticated user, including those with Subscriber or Customer roles, to cancel and void booking orders belonging to other customers.
Recommendations
Update WPS Bookings for WooCommerce WordPress plugin to version 3.11.7 or later.
Exploit
Fix
DoS
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wps Bookings For Woocommerce