CVE-2023-24388: WordPress Booking calendar, Appointment Booking System Plugin <= 3.2.3 is vulnerable to Cross Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions affects plugin forms actions (create, duplicate, edit, delete).
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-24388?
CVE-2023-24388 is a Cross-Site Request Forgery (CSRF) vulnerability in the WpDevArt Booking calendar, Appointment Booking System plugin.
How does CVE-2023-24388 affect the WpDevArt Booking calendar plugin?
CVE-2023-24388 affects the forms actions of the WpDevArt Booking calendar plugin, including create, duplicate, edit, and delete.
What is the severity of CVE-2023-24388?
The severity of CVE-2023-24388 is medium, with a severity value of 5.4.
How can I fix CVE-2023-24388?
To fix CVE-2023-24388, you should update the WpDevArt Booking calendar, Appointment Booking System plugin to version 3.2.4 or higher.
Where can I find more information about CVE-2023-24388?
You can find more information about CVE-2023-24388 at the following link: [https://patchstack.com/database/vulnerability/booking-calendar/wordpress-booking-calendar-appointment-booking-system-plugin-3-2-3-cross-site-request-forgery-csrf?_s_id=cve](https://patchstack.com/database/vulnerability/booking-calendar/wordpress-booking-calendar-appointment-booking-system-plugin-3-2-3-cross-site-request-forgery-csrf?_s_id=cve)