Lucene search

K
wpvulndbSushil PhuyalWPVDB-ID:EB383600-0CFF-4F24-8127-1FB118F0565A
HistoryFeb 28, 2024 - 12:00 a.m.

Booking Calendar < 1.3.83 - CSRF appointment scheduling

2024-02-2800:00:00
Sushil Phuyal
wpscan.com
3
csrf
calendar
vulnerability
unauthorized booking

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Description The plugin does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding a booking to the calendar without paying.

PoC

CPENameOperatorVersion
eq1.3.83

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for WPVDB-ID:EB383600-0CFF-4F24-8127-1FB118F0565A