The Bookster  WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.
                
            Metrics
Affected Vendors & Products
References
        History
                    Mon, 19 May 2025 21:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Wpbookster Wpbookster bookster | |
| CPEs | cpe:2.3:a:wpbookster:bookster:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products | Wpbookster Wpbookster bookster | 
Mon, 28 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-863 | |
| Metrics | cvssV3_1 
 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: WPScan
Published: 2024-06-26T06:00:04.151Z
Updated: 2024-10-28T20:13:18.059Z
Reserved: 2024-05-17T14:55:43.858Z
Link: CVE-2024-5071
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-01T21:03:10.655Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2024-06-26T06:15:16.463
Modified: 2025-05-19T21:02:30.093
Link: CVE-2024-5071
 Redhat
                        Redhat
                    No data.
 ReportizFlow
ReportizFlow