CVE-2019-12239: Wpbookingsystem Wp Booking System
High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.
The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL injection issues that require administrative access.
Affected products
- Wpbookingsystem Wp Booking System: before 1.5.2 (fixed in 1.5.2)
Published 2019-05-20. Last modified 2026-06-17.