Lucene search

K
wpvulndbWpvulndbWPVDB-ID:3C339DE9-BBE1-46B5-938B-7C4A7033F905
HistoryMay 03, 2024 - 12:00 a.m.

WP Travel Engine < 5.8.1 - Unauthenticated Price Manipulation

2024-05-0300:00:00
wpscan.com
9
wordpress
travel booking
price manipulation
vulnerability
unauthenticated attackers

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Description The WP Travel Engine – Best Travel Booking WordPress Plugin plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 5.8.0. This is due to the plugin not properly validating a price. This makes it possible for unauthenticated attackers to manipulate the price of bookings.

CPENameOperatorVersion
eq5.8.1

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for WPVDB-ID:3C339DE9-BBE1-46B5-938B-7C4A7033F905