Filtered by vendor Fs-code Subscriptions
Filtered by product Booknetic Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-13146 1 Fs-code 1 Booknetic 2025-04-30 8.8 High
The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow attackers to make logged in admin add arbitrary Staff members via a CSRF attack