CVE-2024-9450

The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:syntactics:free_booking_plugin_for_hotels\,_restaurant_and_car_rental:*:*:*:*:*:wordpress:*:*

History

04 Jun 2025, 20:06

Type Values Removed Values Added
CWE CWE-352
CPE cpe:2.3:a:syntactics:free_booking_plugin_for_hotels\,_restaurant_and_car_rental:*:*:*:*:*:wordpress:*:*
References () https://wpscan.com/vulnerability/f4b9568a-af74-40df-89c1-550e8515ca0a/ - () https://wpscan.com/vulnerability/f4b9568a-af74-40df-89c1-550e8515ca0a/ - Exploit, Third Party Advisory
First Time Syntactics free Booking Plugin For Hotels\, Restaurant And Car Rental
Syntactics

16 May 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

16 May 2025, 14:42

Type Values Removed Values Added
Summary
  • (es) El complemento Free Booking Plugin for Hotels, Restaurants and Car Rentals de WordPress anterior a la versión 1.3.15 no tiene la comprobación CSRF activada al actualizar su configuración, lo que podría permitir a los atacantes hacer que un suscriptor que haya iniciado sesión la cambie mediante un ataque CSRF.

15 May 2025, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-15 20:16

Updated : 2025-06-04 20:06


NVD link : CVE-2024-9450

Mitre link : CVE-2024-9450

CVE.ORG link : CVE-2024-9450


JSON object : View

Products Affected

syntactics

  • free_booking_plugin_for_hotels\,_restaurant_and_car_rental
CWE
CWE-352

Cross-Site Request Forgery (CSRF)