CVE-2019-12239: Wpbookingsystem Wp Booking System

High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.

The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL injection issues that require administrative access.

Affected products

Published 2019-05-20. Last modified 2026-06-17.