
CVE-2026-1508 The Court Reservation WordPress plugin before 1.10.9 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin dele… https://www.cve.org/CVERecord?id=CVE-2026-1508
Post summary
The post announces a CSRF flaw in the Court Reservation WordPress plugin before v1.10.9 that lets logged‑in admins delete events, with no evidence of exploitation or patch availability.

