High severity7.2NVD Advisory· Published May 20, 2019· Updated Jun 17, 2026
CVE-2019-12239
CVE-2019-12239
Description
The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL injection issues that require administrative access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:wpbookingsystem:wp_booking_system:*:*:*:*:*:wordpress:*:*Range: <1.5.2
- WordPress/WP Booking System plugindescription
- Range: <1.5.1
Patches
Vulnerability mechanics
References
3- dumpco.re/bugs/wp-plugin-wp-booking-system-sqlinvdExploitThird Party Advisory
- wpvulndb.com/vulnerabilities/9284nvdThird Party Advisory
- wordpress.org/plugins/wp-booking-system/nvdRelease Notes
News mentions
0No linked articles in our index yet.