vulnerability

WordPress Plugin: wp-booking-system: CVE-2019-12239: Cross-Site Request Forgery (CSRF)

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
May 22, 2019
Added
May 15, 2025
Modified
May 15, 2025

Description

The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL injection issues that require administrative access.

Solution

wp-booking-system-plugin-cve-2019-12239
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.