8.8

CVE-2023-25707

WordPress VikBooking Hotel Booking Engine & PMS Plugin <= 1.5.12 is vulnerable to Cross Site Request Forgery (CSRF)

VikBooking Hotel Booking Engine & PMS <= 1.5.12 - Cross-Site Request Forgery in admin_widgets_welcome function

VikBooking Hotel Booking Engine & PMS <= 1.5.12 - Cross-Site Request Forgery in saveconfig function

VikBooking Hotel Booking Engine & PMS <= 1.5.12 - Cross-Site Request Forgery in savetmplfile function

VikBooking Hotel Booking Engine & PMS <= 1.5.12 - Cross-Site Request Forgery in exec_multitask_widgets function

VikBooking Hotel Booking Engine & PMS <= 1.5.12 - Cross-Site Request Forgery in widgets_watch_data function

VikBooking Hotel Booking Engine & PMS <= 1.5.12 - Cross-Site Request Forgery in exec_admin_widget function

VikBooking Hotel Booking Engine & PMS <= 1.5.12 - Cross-Site Request Forgery in savetranslation function

VikBooking Hotel Booking Engine & PMS <= 1.5.12 - Cross-Site Request Forgery in savetranslationstay function

VikBooking Hotel Booking Engine & PMS <= 1.5.12 - Cross-Site Request Forgery in save_admin_widgets function

Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.12 versions.
Mögliche Gegenmaßnahme
VikBooking Hotel Booking Engine & PMS: Update to version 1.6.0, or a newer patched version
VikBooking Hotel Booking Engine & PMS: Update to version 1.6.0, or a newer patched version
VikBooking Hotel Booking Engine & PMS: Update to version 1.6.0, or a newer patched version
VikBooking Hotel Booking Engine & PMS: Update to version 1.6.0, or a newer patched version
VikBooking Hotel Booking Engine & PMS: Update to version 1.6.0, or a newer patched version
VikBooking Hotel Booking Engine & PMS: Update to version 1.6.0, or a newer patched version
VikBooking Hotel Booking Engine & PMS: Update to version 1.6.0, or a newer patched version
VikBooking Hotel Booking Engine & PMS: Update to version 1.6.0, or a newer patched version
VikBooking Hotel Booking Engine & PMS: Update to version 1.6.0, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VikwpVikbooking Hotel Booking Engine & Pms SwPlatformwordpress Version < 1.6.0
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt VikBooking Hotel Booking Engine & PMS
Version *-1.5.12
SystemWordPress Plugin
Produkt VikBooking Hotel Booking Engine & PMS
Version *-1.5.12
SystemWordPress Plugin
Produkt VikBooking Hotel Booking Engine & PMS
Version *-1.5.12
SystemWordPress Plugin
Produkt VikBooking Hotel Booking Engine & PMS
Version *-1.5.12
SystemWordPress Plugin
Produkt VikBooking Hotel Booking Engine & PMS
Version *-1.5.12
SystemWordPress Plugin
Produkt VikBooking Hotel Booking Engine & PMS
Version *-1.5.12
SystemWordPress Plugin
Produkt VikBooking Hotel Booking Engine & PMS
Version *-1.5.12
SystemWordPress Plugin
Produkt VikBooking Hotel Booking Engine & PMS
Version *-1.5.12
SystemWordPress Plugin
Produkt VikBooking Hotel Booking Engine & PMS
Version *-1.5.12
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.138
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
audit@patchstack.com 6.3 2.8 3.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

https://patchstack.com/database/vulnerability/vikbooking/wordpress-vikbooking-hotel-booking-engine-pms-plugin-1-5-12-cross-site-request-forgery-csrf-vulnerability?_s_id=cve
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/035d5f4a-1145-48e0-8388-e319088ebd52
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/385c6324-3d8e-4dc7-b8ca-309b05e7bdcc
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/4ad32ff7-0557-439d-aa0f-49c5ea4271ab
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/6adc0154-169a-4d72-8687-66dbf6766139
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/b07b46a6-8a5d-40cb-8af9-baf0f1722736
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/b5ef15c4-c96b-4e88-a941-e34d23a0e06a
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/d0631ac6-2d85-4073-be2c-05480deecf97
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/d2594cef-6bde-425f-9412-fd4ed3da312e
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/e2945971-80c6-44a2-bc65-1243af365692
Third Party Advisory