SQL Injection Vulnerability in WP Booking System Plugin by WordPress
CVE-2019-12239
7.2HIGH
Summary
The WP Booking System plugin version 1.5.1 for WordPress lacks adequate Cross-Site Request Forgery (CSRF) protection, thereby exposing it to potential SQL injection vulnerabilities. Attackers with administrative access can exploit this flaw, leading to unauthorized database manipulation and data leakage, significantly compromising the security of the WordPress site. Administrators should promptly update the plugin and implement security measures to mitigate this risk.
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved