
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1508 is a Cross-Site Request Forgery (CSRF) vulnerability in the Court Reservation WordPress plugin that allows unauthenticated attackers to trick a logged-in administrator into deleting all events. It affects all versions of the plugin before 1.10.9 and was publicly disclosed on February 17, 2026, with NVD publication on March 10, 2026. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (WPScan, Red Hat CVE).
The root cause is a missing CSRF token validation (CWE-352) on the event deletion functionality within the Court Reservation plugin's admin interface. An attacker can craft a malicious HTML page containing a form that auto-submits a POST request to the plugin's event deletion endpoint (/wp-admin/admin.php?page=courtres-event), which the server processes without verifying the request's origin. Exploitation requires no privileges on the part of the attacker but does require user interaction — specifically, a logged-in WordPress administrator must be socially engineered into visiting the attacker-controlled page. A working proof-of-concept was published alongside the disclosure by researcher Bob Matyas (WPScan).
Successful exploitation results in the deletion of all events managed by the Court Reservation plugin, causing a loss of data integrity and availability for the affected WordPress site's reservation system. There is no confidentiality impact, as the attack does not expose sensitive data. The impact is limited in scope to the plugin's event data, but for organizations relying on the plugin for court or facility bookings, mass event deletion could cause significant operational disruption (WPScan, Red Hat CVE).
A public proof-of-concept exploit was released alongside the vulnerability disclosure on February 17, 2026, making exploitation straightforward for any attacker capable of delivering a malicious HTML page to an administrator. The EPSS score is very low at 0.003%, reflecting limited observed exploitation activity. There is no evidence of in-the-wild exploitation, threat actor attribution, or inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (WPScan, Red Hat CVE).
/wp-admin/admin.php?page=courtres-event) with the appropriate POST parameters to delete events.DOMContentLoaded, setTimeout, window.onload) to maximize reliability./wp-admin/admin.php?page=courtres-event from unusual referrer origins or with a missing/empty Referer header, particularly if followed by mass event deletion.Referer header value.The vendor has released version 1.10.9 of the Court Reservation WordPress plugin, which adds proper CSRF token validation to the event deletion functionality. Site administrators should update the plugin to version 1.10.9 or later immediately. No configuration-based workaround is available; upgrading is the only effective remediation (WPScan).
The vulnerability was discovered and responsibly disclosed by researcher Bob Matyas, who also submitted the finding to WPScan. No significant vendor statements beyond the plugin update, major media coverage, or notable community discussion have been identified for this moderate-severity issue.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."