First published: Wed Mar 20 2024(Updated: )
The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding a booking to the calendar without paying.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
CodePeople Appointment Hour Booking | <1.3.83 | |
Booking Calendar | <1.3.83 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0856 has a moderate severity level due to its potential for CSRF attacks that can manipulate user actions.
To fix CVE-2024-0856, update the Appointment Booking Calendar WordPress plugin to version 1.3.83 or later.
Users of affected versions may be susceptible to unauthorized actions being performed on their behalf by attackers.
CVE-2024-0856 affects the Appointment Booking Calendar plugin versions prior to 1.3.83.
CVE-2024-0856 is specific to the Appointment Booking Calendar WordPress plugin, making it less common across other software.