CVE-2025-46241: WordPress Appointment Booking Calendar plugin <= 1.3.92 - CSRF to SQL Injection vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows SQL Injection.This issue affects Appointment Booking Calendar: from n/a through <= 1.3.92.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46241?
CVE-2025-46241 is considered a critical vulnerability due to its ability to facilitate SQL Injection through Cross-Site Request Forgery.
How do I fix CVE-2025-46241?
To fix CVE-2025-46241, update the Appointment Booking Calendar plugin to the latest version beyond 1.3.92.
Which versions of the Appointment Booking Calendar are affected by CVE-2025-46241?
CVE-2025-46241 affects all versions up to and including 1.3.92 of the Appointment Booking Calendar.
What type of vulnerability is CVE-2025-46241?
CVE-2025-46241 is a Cross-Site Request Forgery (CSRF) vulnerability that leads to SQL Injection.
Can CVE-2025-46241 lead to data breaches?
Yes, CVE-2025-46241 can potentially allow attackers to exploit SQL Injection, leading to data breaches.