Lucene search

K
wpvulndbWpvulndbWPVDB-ID:DCA1DDF5-C3C3-4D60-9E92-FA01BDC55E1C
HistorySep 06, 2022 - 12:00 a.m.

Booking Calendar < 9.2.2 - Arbitrary Translation Update via CSRF

2022-09-0600:00:00
wpscan.com
4
plugin
csrf
update
translation
attack
software

0.001 Low

EPSS

Percentile

21.0%

The plugin does not have CSRF check when updating translations, which could allow attackers to make logged in users update arbitrary translations via a CSRF attack

CPENameOperatorVersion
bookinglt9.2.2

0.001 Low

EPSS

Percentile

21.0%

Related for WPVDB-ID:DCA1DDF5-C3C3-4D60-9E92-FA01BDC55E1C