Input validation vulnerability in Booking Calendar Contact Form 1.2.34

The Booking Calendar Contact Form plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This means that if versions of the plugin up to and including 1.2.34 are being used, it could be possible for unauthenticated attackers to submit feedback forms without permission. This is because the plugin is missing or incorrect validation for something called a nonce on the cpdexbccf_feedback function when called via the cpdexbccf_feedback AJAX action. To take advantage of this vulnerability, the unauthenticated attacker would need to trick the site administrator into performing an action such as clicking on a link.

Detected in:

Booking Calendar Contact Form fixed vulnerable versions: >= * <= 1.2.34

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.