CVE-2026-1508 PUBLISHED

Court Reservation < 1.10.9 - Event Deletion via CSRF

Assigner: WPScan
Reserved: 27.01.2026 Published: 10.03.2026 Updated: 10.03.2026

The Court Reservation WordPress plugin before 1.10.9 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin delete them via a CSRF attack

Product Status

Vendor Unknown
Product Court Reservation
Versions Default: unaffected
  • affected from 0 to 1.10.9 (excl.)

Credits

  • Bob Matyas finder
  • WPScan coordinator

References

Problem Types

  • CWE-352 Cross-Site Request Forgery (CSRF) CWE