CVE-2024-0856: Booking Calendar < 1.3.83 - CSRF appointment scheduling
The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding a booking to the calendar without paying.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0856?
CVE-2024-0856 has a moderate severity level due to its potential for CSRF attacks that can manipulate user actions.
How do I fix CVE-2024-0856?
To fix CVE-2024-0856, update the Appointment Booking Calendar WordPress plugin to version 1.3.83 or later.
What are the implications of CVE-2024-0856 for users?
Users of affected versions may be susceptible to unauthorized actions being performed on their behalf by attackers.
Which software versions are affected by CVE-2024-0856?
CVE-2024-0856 affects the Appointment Booking Calendar plugin versions prior to 1.3.83.
Is CVE-2024-0856 a common vulnerability?
CVE-2024-0856 is specific to the Appointment Booking Calendar WordPress plugin, making it less common across other software.