PT-2026-68647 · WordPress · Easync Booking
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Easy Booking WordPress plugin versions prior to 3.5.0
Description
The plugin fails to enforce the configured minimum booking duration on the server side during the process of adding a product to the cart and calculating the booking price. This allows unauthenticated users to create bookings that are shorter than the required minimum and complete orders with prices lower than intended.
Recommendations
Update Easy Booking WordPress plugin to version 3.5.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easync Booking