CyberRota Analysis
AI-GeneratedThe Booking for Appointments and Events Calendar WordPress plugin prior to version 2.4.4 is vulnerable due to inadequate restrictions on fields during customer imports, enabling users with the Amelia Manager role to alter any stored user record. This could lead to unauthorized modifications of sensitive user data, posing a significant risk to user privacy and data integrity. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.
Original NVD Description
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.