Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-24125 | The CBX Restaurant Booking WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack |
Fri, 09 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-352 |
Tue, 12 Aug 2025 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Mon, 11 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 11 Aug 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The CBX Restaurant Booking WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Title | CBX Restaurant Booking <= 1.2.1 - Plugin Reset via CSRF | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-01-09T20:20:49.331Z
Reserved: 2025-07-21T17:55:20.962Z
Link: CVE-2025-7965
Updated: 2025-08-11T14:55:10.987Z
Status : Deferred
Published: 2025-08-11T06:15:26.900
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-7965
No data.
OpenCVE Enrichment
Updated: 2025-08-12T07:45:33Z
EUVD