First published: Tue Oct 31 2023(Updated: )
The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
<3.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2023-5519.
The severity of CVE-2023-5519 is medium with a CVSS score of 4.3.
This vulnerability affects the EventPrime WordPress plugin version up to but excluding 3.2.0.
The potential consequences of CVE-2023-5519 include attackers being able to make logged in users create unwanted bookings via CSRF attacks.
To mitigate the risk associated with CVE-2023-5519, it is recommended to update the EventPrime plugin to version 3.2.0 or higher.