The Appointment Hour Booking plugin for WordPress is...
Moderate severity
Unreviewed
Published
Nov 29, 2022
to the GitHub Advisory Database
•
Updated Jul 19, 2023
Description
Published by the National Vulnerability Database
Nov 29, 2022
Published to the GitHub Advisory Database
Nov 29, 2022
Last updated
Jul 19, 2023
The Appointment Hour Booking plugin for WordPress is vulnerable to CAPTCHA bypass in versions up to, and including, 1.3.72. This is due to the use of insufficiently strong hashing algorithm on the CAPTCHA secret that is also displayed to the user via a cookie.
References