Vulnerabilities
Vulnerable Software
Themetechmount:  >> Truebooker  Security Vulnerabilities
Cross-Site Request Forgery (CSRF) vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Cross Site Request Forgery.This issue affects TrueBooker: from n/a through <= 1.0.7.
CVSS Score
4.3
EPSS Score
0.001
Published
2025-05-07
The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
CVSS Score
9.8
EPSS Score
0.765
Published
2024-09-08
The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
CVSS Score
4.3
EPSS Score
0.002
Published
2024-09-08


Contact Us

Shodan ® - All rights reserved