VYPR
Unrated severityNVD Advisory· Published Sep 24, 2024· Updated Apr 8, 2026

BA Book Everything <= 1.6.20 - Cross-Site Request Forgery to Email Address Update/Account Takeover

CVE-2024-8795

Description

The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.20. This is due to missing or incorrect nonce validation on the my_account_update() function. This makes it possible for unauthenticated attackers to update a user's account details via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This can be leveraged to reset a user's password and gain access to their account.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.