ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

CVE-2026-11866

MEDIUM Export PDF

The Appointment Booking Plugin WordPress plugin before 5

The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central request dispatcher, allowing attackers to perform privileged actions, such as overwriting the booking-form configuration or disconnecting the connected payment gateway, via Cross-Site Request Forgery against a logged-in administrator.

CVSS Score
5.4
MEDIUM
Published
16 Jul 2026 07:16
Modified
16 Jul 2026 16:18
Vendor
WordPress Plugin
Source
CIRCL

CVSS v3 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Attack Vector
Network
Complexity
Low
Privileges
None
Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low

Weaknesses (CWE)

CWE-352

Affected Systems

WordPress Plugin

KEV Status

Not in CISA KEV catalog