Vulnerabilities
Vulnerable Software
Themetechmount:  Security Vulnerabilities
Cross-Site Request Forgery (CSRF) vulnerability in themetechmount TrueBooker allows Cross Site Request Forgery. This issue affects TrueBooker: from n/a through 1.0.7.
CVSS Score
4.3
EPSS Score
0.0
Published
2025-05-07
The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
CVSS Score
9.8
EPSS Score
0.755
Published
2024-09-08
The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
CVSS Score
4.3
EPSS Score
0.001
Published
2024-09-08


Contact Us

Shodan ® - All rights reserved