Impact
Cross‑Site Request Forgery (CSRF) vulnerability in the fs‑code Booknetic WordPress plugin allows an attacker to forge authenticated requests on behalf of a logged‑in user. By tricking a user into visiting a malicious page or submitting a forged form, the attacker can potentially modify booking settings, create or delete bookings, or otherwise alter data managed by the plugin. The flaw arises from inadequate verification of request integrity and is classified as CWE‑352.
Affected Systems
WordPress Booknetic plugin distributed by fs‑code. All versions up through 4.0.9 are affected; the issue is reported for every build from version n/a to 4.0.9.
Risk and Exploitability
The CVSS score of 4.3 indicates low‑to‑medium severity. The EPSS score of less than 1% suggests a very low exploitation probability at present, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the victim to be authenticated to the site, so the impact depends on the privileges of the user whose session is hijacked. An attacker could perform unauthorized changes, but larger damage would require elevated rights or additional weaknesses.
OpenCVE Enrichment
EUVD