CVE-2024-12274
13.01.2025, 06:15
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.1.23 export settings functionality exports data to a public folder, with an easily guessable file name, allowing unauthenticated attackers to access the exported files (if they exist).Enginsight
| Vendor | Product | Version |
|---|---|---|
| codepeople | appointment_booking_calendar | 𝑥 < 1.1.23 |
𝑥
= Vulnerable software versions