The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/f4b9568a-af74-40df-89c1-550e8515ca0a/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
04 Jun 2025, 20:06
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-352 | |
CPE | cpe:2.3:a:syntactics:free_booking_plugin_for_hotels\,_restaurant_and_car_rental:*:*:*:*:*:wordpress:*:* | |
References | () https://wpscan.com/vulnerability/f4b9568a-af74-40df-89c1-550e8515ca0a/ - Exploit, Third Party Advisory | |
First Time |
Syntactics free Booking Plugin For Hotels\, Restaurant And Car Rental
Syntactics |
16 May 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
16 May 2025, 14:42
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
15 May 2025, 20:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-15 20:16
Updated : 2025-06-04 20:06
NVD link : CVE-2024-9450
Mitre link : CVE-2024-9450
CVE.ORG link : CVE-2024-9450
JSON object : View
Products Affected
syntactics
- free_booking_plugin_for_hotels\,_restaurant_and_car_rental
CWE
CWE-352
Cross-Site Request Forgery (CSRF)