
Cloud Vulnerability DB
A community-led vulnerabilities database
The Multi-Scheduler plugin version 1.0.0 for WordPress contains a Cross-Site Request Forgery (CSRF) vulnerability (CVE-2020-13426). The vulnerability was discovered on May 21, 2020, and affects the forms presented by the plugin, which lack proper CSRF protection mechanisms. The plugin was designed to manage event reservations, including appointments, meetings, and interviews, with calendar functionality and user management capabilities (CX Security, Infayer).
The vulnerability stems from the absence of anti-CSRF tokens in forms that handle user deletion and creation operations. This security oversight places complete trust in user actions without proper validation. The CVSS v3.1 base score is 6.5 (MEDIUM) with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N, indicating a network-accessible vulnerability requiring user interaction (NVD).
The vulnerability allows attackers to force authenticated users to perform unintended actions, specifically the deletion of user records from the 'professional' table in the application database when the target user ID is known. This can lead to unauthorized deletion of user data without the victim's consent (CX Security, Infayer).
Proof of Concept (PoC) exploits have been published demonstrating how an attacker can craft a malicious form that, when submitted by an authenticated user, triggers the unauthorized deletion of user records. The vulnerability has been documented in multiple security databases and exploit repositories (Exploit DB, Packet Storm).
The plugin has been closed and is no longer available for download as of June 1, 2020, due to this security issue. Users are advised to remove the plugin from their WordPress installations to prevent potential exploitation (WordPress).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."