- Description
- The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_db function in all versions up to, and including, 4.9.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to expose sensitive information from the database, such as the hashed administrator password.
- Source
- security@wordfence.com
- NVD status
- Received
CVSS 3.1
- Type
- Primary
- Base score
- 6.5
- Impact score
- 3.6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
- security@wordfence.com
- CWE-862
- Hype score
- Not currently trending
🚨🛠️ Added CVE-2024-12558 proof-of-concept for WP BASE Booking of Appointments, Services and Events plugin for WordPress info disclosure vuln into #CyberSecFolio. https://t.co/wHv4FwYoiZ #infosec #cyber #security Vulnerability description 👇 https://t.co/4sXOSy7vzW
@gothburz
12 Jan 2025
46 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE Alert: CVE-2024-12558 - https://t.co/ApOmIywY7K #OSINT #ThreatIntel #CyberSecurity #cve_2024_12558
@RedPacketSec
22 Dec 2024
88 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-12558 Unauthorized Data Exposure in WP BASE Booking Plugin 4.9.... https://t.co/lEmKIY67Qt Don't wait vulnerability scanning results: https://t.co/oh1APvMMnd
@VulmonFeeds
21 Dec 2024
42 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-12558 The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ex… https://t.co/B8S7FOr238
@CVEnew
21 Dec 2024
829 Impressions
1 Retweet
1 Like
1 Bookmark
0 Replies
0 Quotes