Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-0856


The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding a booking to the calendar without paying.


Published

2024-03-20T05:15:45.433

Last Modified

2025-05-05T18:41:08.043

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-352

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application codepeople appointment_booking_calendar < 1.3.83 Yes

References