Vulnerabilities > BA Booking

DATE CVE VULNERABILITY TITLE RISK
2024-09-24 CVE-2024-8794 Unspecified vulnerability in Ba-Booking BA Book Everything
The BA Book Everything plugin for WordPress is vulnerable to arbitrary password reset in all versions up to, and including, 1.6.20.
network
low complexity
ba-booking
5.3
2024-09-24 CVE-2024-8795 Cross-Site Request Forgery (CSRF) vulnerability in Ba-Booking BA Book Everything
The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.20.
network
low complexity
ba-booking CWE-352
8.8