CVE-2025-54036: WordPress Webba Booking plugin <= 5.1.20 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Webba Appointment Booking Webba Booking allows Cross Site Request Forgery. This issue affects Webba Booking: from n/a through 5.1.20.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Webba Appointment Booking Webba Booking webba-booking-lite allows Cross Site Request Forgery.This issue affects Webba Booking: from n/a through <= 5.1.20.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54036?
The severity of CVE-2025-54036 is considered to be moderate due to its potential for exploitation via Cross-Site Request Forgery.
How do I fix CVE-2025-54036?
To mitigate CVE-2025-54036, update the Webba Booking plugin to a version higher than 5.1.20.
What versions are affected by CVE-2025-54036?
CVE-2025-54036 affects Webba Booking plugin versions from n/a up to and including 5.1.20.
What type of attack does CVE-2025-54036 facilitate?
CVE-2025-54036 facilitates Cross-Site Request Forgery (CSRF) attacks, allowing unauthorized actions on behalf of authenticated users.
Who is impacted by CVE-2025-54036?
Users of Webba Booking and the WordPress Webba Booking plugin up to version 5.1.20 are impacted by CVE-2025-54036.