CVE-2024-6175: Deetronix Booking Ultra Pro Appointments Booking Calendar Plugin
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the multiple functions called via AJAX like save_fields_settings, bup_delete_user_avatar, bup_crop_avatar_user_profile_image, and more in all versions up to, and including, 1.1.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify and delete. multiple plugin options and data such as payments, pricing, booking information, business hours, calendars, profile information, and email templates.
Affected products
- Deetronix Booking Ultra Pro Appointments Booking Calendar Plugin: up to and including 1.1.13
Published 2024-07-18. Last modified 2026-06-17.