CVE-2024-12274
13.01.2025, 06:15
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.1.23 export settings functionality exports data to a public folder, with an easily guessable file name, allowing unauthenticated attackers to access the exported files (if they exist).Enginsight
Vendor | Product | Version |
---|---|---|
codepeople | appointment_booking_calendar | 𝑥 < 1.1.23 |
𝑥
= Vulnerable software versions