CVE-2023-4251: EventPrime < 3.2.0 - Booking Creation via CSRF
The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-4251?
The severity of CVE-2023-4251 is medium with a CVSS score of 4.3.
How does CVE-2023-4251 affect the EventPrime plugin?
CVE-2023-4251 affects the EventPrime WordPress plugin before version 3.2.0.
What is the vulnerability description of CVE-2023-4251?
CVE-2023-4251 is a Cross-Site Request Forgery (CSRF) vulnerability in EventPrime plugin that allows attackers to create unwanted bookings using logged-in user credentials.
How can an attacker exploit CVE-2023-4251?
An attacker can exploit CVE-2023-4251 by tricking a logged-in user into visiting a malicious website that performs unauthorized booking creation via CSRF attacks.
Are there any references for CVE-2023-4251?
Yes, you can find more information about CVE-2023-4251 at the following reference: [link](https://wpscan.com/vulnerability/ce564628-3d15-4bc5-8b8e-60b71786ac19)