CVE-2022-33177
The Booking Calendar plugin for WordPress through version 9.2.1 contains a Cross-Site Request Forgery vulnerability in the wpbc_translation_buttons_settings_section function due to insufficient nonce verification. An unauthenticated attacker could exploit this flaw by crafting a malicious request that, if clicked by an authenticated site administrator, would allow modification of translation settings. The vulnerability was resolved in version 9.2.2.
Based on public CVE data (MITRE/NVD).