Vulnerability CVE-2024-1634


Published: 2024-06-18

Description:
The Scheduling Plugin ?? Online Booking for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'cbsb_disconnect_settings' function in all versions up to, and including, 3.5.10. This makes it possible for unauthenticated attackers to disconnect the plugin from the startbooking service and remove connection data.

 References:
https://www.wordfence.com/threat-intel/vulnerabilities/id/60e642f9-74ff-47f1-a49d-99c8fdb26f4a?source=cve
https://wordpress.org/plugins/calendar-booking/

Copyright 2026, cxsecurity.com

 

Back to Top