What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows SQL Injection.This issue affects Appointment Booking Calendar: from n/a through <= 1.3.92.
Explanation of Vulnerability in Simple Terms
02Summary
Appointment Booking Calendar versions up to 1.3.92 contain a cross-site request forgery (CSRF) vulnerability that allows attackers to perform unauthorized actions on behalf of site visitors. An attacker can craft a malicious link or page that, when visited by a logged-in user, executes unwanted requests against the plugin. This can lead to unauthorized data modification and service disruption.
What an attacker can do
03Attacker Capabilities
Perform unauthorized actions on behalf of a logged-in user, such as modifying appointments or settings.
Potential impact on your site
04Site Impact
Visitors' appointment data could be altered or deleted without their knowledge; site availability may be affected.
Conditions required to exploit
05Prerequisites
A site visitor must click a malicious link or visit an attacker-controlled page while logged into the site.
Key dates
06Disclosure timeline
April 22, 2025
CVE published
April 28, 2026
Record updated