CVE-2024-30516

7.5

SaasProject · Booking Package

An improper input validation flaw in the SaasProject Booking Package plugin allows unauthenticated users to bypass access control lists and manipulate pricing.

Executive summary

A critical input validation vulnerability in the SaasProject Booking Package plugin allows unauthenticated attackers to perform unauthorized price manipulation, posing a significant financial risk.

Vulnerability

This vulnerability involves improper validation of input quantities, which enables unauthenticated actors to bypass access control constraints. By submitting specifically crafted inputs, an attacker can manipulate pricing logic within the plugin.

Business impact

The ability for unauthenticated users to manipulate product pricing represents a direct threat to revenue integrity and business operations. With a CVSS score of 7.5, this high-severity vulnerability could lead to significant financial loss and damage to customer trust if exploited to purchase services at unauthorized rates.

Remediation

Immediate Action: Update the WordPress Booking Package plugin to version 1.6.29 or higher to resolve the input validation flaw.

Proactive Monitoring: Review transaction logs and pricing audit trails for anomalous activity, specifically looking for orders containing unexpected or zero-value quantities.

Compensating Controls: Implement a Web Application Firewall (WAF) rule to inspect and block requests containing suspicious input parameters or payloads directed at the booking functionality.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for direct financial exploitation, users of the SaasProject Booking Package should prioritize updating to version 1.6.29 immediately. Failure to patch leaves the booking system vulnerable to price manipulation by any remote, unauthenticated attacker.

Sources

Originally found and disclosed by Abdi Pranata | Patchstack Bug Bounty Progran, per the CVE Program record.