Input validation vulnerability in Booking Plugin for WordPress Appointments – Time Slot 1.4.7

The Booking Plugin for WordPress Appointments – Time Slot plugin has a security vulnerability that allows unauthorized sending of emails. This can happen in versions 1.4.7 and below because there is no validation for the tslot_appt_email AJAX action. This means that people who are not logged in can send appointment notification emails to anyone they want, and they can also control the text in certain parts of the email. This could be used by attackers to send phishing emails or spam.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.