CVE · Medium

CVE-2022-36399 — Booked [booked] < 2.4.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-36399 Booked [booked] < 2.4.4 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 2.4.4 2.4.4 2023-06-27

CVE-2022-36399

The Booked appointment booking plugin for WordPress before version 2.4.4 contains a vulnerability that exposes sensitive information to unauthorized users. This flaw allows attackers to access confidential data that should be restricted. The vulnerability impacts all installations running versions prior to 2.4.4 and is resolved in version 2.4.4 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.