HomeDefault status
affected
Any version
affected
Description
The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthenticated attacker to delete any customer through a CSRF attack.
Problem types
CWE-352 Cross-Site Request Forgery (CSRF)
Product status
Any version
Credits
Drtime
WPScan
References
wpscan.com/...rability/e5ba488a-b43d-4c5f-9716-4b24701999f3/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.