The Appointment Booking Plugin WordPress plugin before 5
The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central request dispatcher, allowing attackers to perform privileged actions, such as overwriting the booking-form configuration or disconnecting the connected payment gateway, via Cross-Site Request Forgery against a logged-in administrator.
CVSS Score
5.4
MEDIUM
Published
16 Jul 2026 07:16
Modified
16 Jul 2026 16:18
Vendor
WordPress Plugin
Source
CIRCL
CVSS v3 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Attack Vector
Network
Complexity
Low
Privileges
None
Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low
Weaknesses (CWE)
CWE-352
Affected Systems
WordPress Plugin
External Links
KEV Status
Not in CISA KEV catalog