The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sending in versions up to, and including, 1.4.7 due to missing validation on the tslot_appt_email AJAX action. This makes it possible for unauthenticated attackers to send appointment notification emails to arbitrary recipients with attacker-controlled text content in certain email fields, potentially enabling the site to be abused for phishing campaigns or spam distribution.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Timeslotplugins
Timeslotplugins booking Plugin For Wordpress Appointments Wordpress Wordpress wordpress |
|
| Vendors & Products |
Timeslotplugins
Timeslotplugins booking Plugin For Wordpress Appointments Wordpress Wordpress wordpress |
Wed, 19 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Nov 2025 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sending in versions up to, and including, 1.4.7 due to missing validation on the tslot_appt_email AJAX action. This makes it possible for unauthenticated attackers to send appointment notification emails to arbitrary recipients with attacker-controlled text content in certain email fields, potentially enabling the site to be abused for phishing campaigns or spam distribution. | |
| Title | Booking Plugin for WordPress Appointments – Time Slot <= 1.4.7 - Unauthenticated Arbitrary Email Sending | |
| Weaknesses | CWE-20 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-11-19T05:45:10.444Z
Updated: 2025-11-19T20:13:20.453Z
Reserved: 2025-11-06T20:19:03.726Z
Link: CVE-2025-12842
Updated: 2025-11-19T20:13:17.522Z
Status : Awaiting Analysis
Published: 2025-11-19T06:15:46.990
Modified: 2025-11-19T19:14:59.327
Link: CVE-2025-12842
No data.