First published: Tue Oct 31 2023(Updated: )
The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
<3.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-4251 is medium with a CVSS score of 4.3.
CVE-2023-4251 affects the EventPrime WordPress plugin before version 3.2.0.
CVE-2023-4251 is a Cross-Site Request Forgery (CSRF) vulnerability in EventPrime plugin that allows attackers to create unwanted bookings using logged-in user credentials.
An attacker can exploit CVE-2023-4251 by tricking a logged-in user into visiting a malicious website that performs unauthorized booking creation via CSRF attacks.
Yes, you can find more information about CVE-2023-4251 at the following reference: [link](https://wpscan.com/vulnerability/ce564628-3d15-4bc5-8b8e-60b71786ac19)