The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2023-10-31T13:54:44.499Z

Updated: 2024-08-02T07:59:44.783Z

Reserved: 2023-10-11T08:04:13.825Z

Link: CVE-2023-5519

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-10-31T14:15:12.893

Modified: 2023-11-08T18:43:21.643

Link: CVE-2023-5519

cve-icon Redhat

No data.