Vulnerabilities (CVE)

Filtered by vendor Fs-code Subscribe
Filtered by product Booknetic
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-13146 1 Fs-code 1 Booknetic 2025-04-30 N/A 8.8 HIGH
The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow attackers to make logged in admin add arbitrary Staff members via a CSRF attack