CVE-2025-12842

The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sending in versions up to, and including, 1.4.7 due to missing validation on the tslot_appt_email AJAX action. This makes it possible for unauthenticated attackers to send appointment notification emails to arbitrary recipients with attacker-controlled text content in certain email fields, potentially enabling the site to be abused for phishing campaigns or spam distribution.
Configurations

No configuration.

History

19 Nov 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-19 06:15

Updated : 2025-11-19 19:14


NVD link : CVE-2025-12842

Mitre link : CVE-2025-12842

CVE.ORG link : CVE-2025-12842


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation