The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.
El complemento Bookster WordPress hasta la versión 1.1.0 permite agregar parámetros confidenciales al validar citas, lo que permite a los atacantes manipular los datos enviados al reservar una cita (el cuerpo de la solicitud) para cambiar su estado de pendiente a aprobado.
The Bookster – WordPress Appointment Booking Plugin plugin for WordPress is vulnerable to unauthorized data manipulation in all versions up to, and including, 1.1.0. This is due to the plugin not properly validating the book_status parameter. This makes it possible for unauthenticated attackers to update their booking status to approved.