The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding a booking to the calendar without paying.
History

Mon, 05 May 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Codepeople
Codepeople appointment Booking Calendar
Weaknesses CWE-352
CPEs cpe:2.3:a:codepeople:appointment_booking_calendar:*:*:*:*:*:wordpress:*:*
Vendors & Products Codepeople
Codepeople appointment Booking Calendar

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-03-20T05:00:02.675Z

Updated: 2024-08-05T18:06:03.929Z

Reserved: 2024-01-24T11:38:06.130Z

Link: CVE-2024-0856

cve-icon Vulnrichment

Updated: 2024-08-01T18:18:18.979Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-20T05:15:45.433

Modified: 2025-05-05T18:41:08.043

Link: CVE-2024-0856

cve-icon Redhat

No data.