← Vulnerability feed

Vulnerability record · CVE-2025-46241 · published 22 April 2025

CVE-2025-46241: Codepeople appointment booking calendar cross-site request forgery vulnerability

Codepeople · Appointment Booking Calendar

Cross-Site Request Forgery (CSRF) vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows SQL Injection.This issue affects Appointment Booking Calendar: from n/a through <= 1.3.92.

8.8 CVSS 3.1 High EPSS 0.19% · top 92.4% CWE-352 · Cross-site request forgery
8.8CVSS 3.1 base score
0.19%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Cross-Site Request Forgery (CSRF) vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows SQL Injection.This issue affects Appointment Booking Calendar: from n/a through <= 1.3.92.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-46241 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-46247Codepeople appointment booking calendar missing authorization vulnerabilityMissing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Accessing Functionality Not Proper…EPSS 0.39%9.8CVE-2016-10916Codepeople appointment booking calendar sql injection vulnerabilityThe appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.EPSS 1.8%8.8CVE-2024-0856Codepeople appointment booking calendar cross-site request forgery vulnerabilityThe Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged …EPSS 0.38%8.8CVE-2022-43482Codepeople appointment booking calendar missing authorization vulnerabilityMissing Authorization vulnerability in Appointment Booking Calendar plugin <= 1.3.69 on WordPress.EPSS 0.54%7.8CVE-2020-9372Codepeople appointment booking calendar csv injection vulnerabilityThe Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to …EPSS 8.6%7.5CVE-2024-12274Codepeople appointment booking calendar vulnerabilityThe Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.1.23 export settings functionality exports data to a public f…EPSS 0.64%7.5CVE-2015-7319Codepeople appointment booking calendar sql injection vulnerabilitySQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPre…EPSS 2.4%6.1CVE-2019-14791Codepeople appointment booking calendar cross-site scripting vulnerabilityThe Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2025-46241), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.