Description
The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sending in versions up to, and including, 1.4.7 due to missing validation on the tslot_appt_email AJAX action. This makes it possible for unauthenticated attackers to send appointment notification emails to arbitrary recipients with attacker-controlled text content in certain email fields, potentially enabling the site to be abused for phishing campaigns or spam distribution.
Problem types
CWE-20 Improper Input Validation
Product status
* (semver)
Timeline
| 2025-11-06: | Vendor Notified |
| 2025-11-18: | Disclosed |
Credits
Md. Moniruzzaman Prodhan
References
www.wordfence.com/...-5da8-44fe-8614-832768444178?source=cve
plugins.trac.wordpress.org/...gs/1.4.6/public/form/email.php
plugins.trac.wordpress.org/...gs/1.4.6/public/form/email.php
plugins.trac.wordpress.org/...timeslot&sfp_email=&sfph_mail=