WP Time Slots Booking Form by CodePeople <= 1.1.76 - Cross-Site Request Forgery (CSRF) to Send Feedback
REPORT ID: 688b1f41-e734-4e8b-9252-61450c6ad2b2
The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check when submitting feedback, which makes it possible for attackers to send feedback via a forged request if they can trick an administrator into performing an action such as clicking on a link.
You need to log in to view the vulnerability details.