Feed/CVE-2026-1508
CVE-2026-1508MEDIUMCVSS 4.3

CVE-2026-1508

Published Mar 10, 2026·Updated Jun 17, 2026

NVD Description

The Court Reservation WordPress plugin before 1.10.9 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin delete them via a CSRF attack

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free