The Scheduling Plugin – Online Booking for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'cbsb_disconnect_settings' function in all versions up to, and including, 3.5.10. This makes it possible for unauthenticated attackers to disconnect the plugin from the startbooking service and remove connection data.
Project Subscriptions
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-17373 | The Scheduling Plugin – Online Booking for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'cbsb_disconnect_settings' function in all versions up to, and including, 3.5.10. This makes it possible for unauthenticated attackers to disconnect the plugin from the startbooking service and remove connection data. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 25 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Startbooking scheduling Plugin
|
|
| CPEs | cpe:2.3:a:startbooking:scheduling_plugin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Startbooking scheduling Plugin
|
|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-01T18:48:20.634Z
Reserved: 2024-02-19T17:10:34.228Z
Link: CVE-2024-1634
Updated: 2024-08-01T18:48:20.634Z
Status : Modified
Published: 2024-06-18T03:15:09.580
Modified: 2024-11-21T08:50:58.150
Link: CVE-2024-1634
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD