Vulnerability Details CVE-2024-1760
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.6.20. This is due to missing or incorrect nonce validation on the ssa_factory_reset() function. This makes it possible for unauthenticated attackers to reset the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.1%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2024-1760
-
cpe:2.3:a:nsquared:simply_schedule_appointments:-
-
cpe:2.3:a:nsquared:simply_schedule_appointments:1.6.6.16
-
cpe:2.3:a:nsquared:simply_schedule_appointments:1.6.6.20
-
cpe:2.3:a:nsquared:simply_schedule_appointments:1.6.6.7