Tock Widget
Tock Widget has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Tock Widget has a vendor fix available, so running the current release closes it.
All of these findings were reported by 0xd4rk5id3. Tock Widget is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2025-22520Tock Widget <= 1.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Tock Widget
Author
Tock
Quickly and easily embed the official Tock booking button and reservation widget into your WordPress site. The button can be inserted into any page of your site, and does not require you to write any custom code. When a user on your site clicks the button installed by this plugin, a booking modal will appear displaying all of your business’ offerings at a glance. It can be used as your website’s primary call to action to allow your guests to begin the reservation process from within your website. More resources Learn more about the Tock widget on the Tock Help Center Need a more custom configuration for your widget? Use our custom widget instead. Visit your Tock dashboard to get started. About Tock Tock helps you take control of your business by offering fully customizable reservations for everyday tables, special tastings, and everything in between. From general admission events to pop-up dinners, Tock’s event platform gives you the tools you need to offer a beautiful booking experience for your guests, and run a well-executed event. Learn more about Tock at https://www.exploretock.com
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C