Vulnerabilities > CVE-2022-2373 - Missing Authorization vulnerability in Nsqua Simply Schedule Appointments

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
nsqua
CWE-862

Summary

The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address

Vulnerable Configurations

Part Description Count
Application
Nsqua
172

Common Weakness Enumeration (CWE)