First published: Mon Jul 17 2023(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Nikola Loncar Easy Appointments plugin <= 3.11.9 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Easy Appointments | <=3.11.9 | |
Easy!Appointments | <=3.11.9 |
Update to 3.11.10 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36424 is a Cross-Site Request Forgery (CSRF) vulnerability in the Nikola Loncar Easy Appointments plugin <= 3.11.9.
CVE-2022-36424 has a severity rating of 8.8 (high).
CVE-2022-36424 affects Nikola Loncar Easy Appointments plugin versions up to and including 3.11.9.
To fix CVE-2022-36424, it is recommended to update the Nikola Loncar Easy Appointments plugin to a version that is not affected by the vulnerability.
You can find more information about CVE-2022-36424 at the following reference: [link](https://patchstack.com/database/vulnerability/easy-appointments/wordpress-easy-appointments-plugin-3-11-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve)