CVE-2023-25707: WordPress VikBooking Hotel Booking Engine & PMS Plugin <= 1.5.12 is vulnerable to Cross Site Request Forgery (CSRF)
Published May 23, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.12 versions.
Affected Software
1 affected component
vikwp Vikbooking Hotel Booking Engine \& Pms Wordpress<1.6.0
Remediation
Information
Update to 1.6.0 or a higher version.
Event History
May 23, 2023
CVE Published
via MITRE·12:36 PM
Data Sourced
via MITRE·12:36 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-25707?
CVE-2023-25707 is a Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin versions <= 1.5.12.
2
What is the severity of CVE-2023-25707?
The severity of CVE-2023-25707 is high with a severity value of 8.8.
3
What software versions are affected by CVE-2023-25707?
The affected software versions of CVE-2023-25707 are VikBooking Hotel Booking Engine & PMS plugin <= 1.5.12.
4
What is the CWE number for CVE-2023-25707?
The CWE number for CVE-2023-25707 is 352.
5
Where can I find more information about CVE-2023-25707?
You can find more information about CVE-2023-25707 at this reference [link](https://patchstack.com/database/vulnerability/vikbooking/wordpress-vikbooking-hotel-booking-engine-pms-plugin-1-5-12-cross-site-request-forgery-csrf-vulnerability?_s_id=cve).