CVE-2024-12558
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2024-12558: The WP BASE Booking plugin for WordPress, used in versions up to 4.9.2, contains a vulnerability where the export_db function lacks proper capability checks. This issue allows authenticated attackers with Subscriber-level access or higher to gain unauthorized access to sensitive data, including administrator passwords, which are stored in hashed form in the database. This vulnerability poses a significant risk to WordPress sites using the WP BASE Booking plugin and should be addressed promptly by updating to the latest version or applying appropriate patches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.